ThreatsCloud & SaaSBreakingCritical F5 BIG-IP APM Heap Overflow Weaponized to Hijack Enterprise Gateway Data Planes CVE-2026-94127F5 confirms active zero-day exploitation of CVE-2026-94127, a critical heap buffer overflow in BIG-IP APM OAuth gateways allowing unauthenticated remote code execution.CST Newsroom·23 Sep 2026, 04:00 IST·17 min read