Home / Sep 24, 2026 / Story
0
#1 The Hacker News general September 23, 2026 at 08:29 UTC

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

By [email protected] (The Hacker News)

AI Summary

F5 disclosed and patched CVE-2026-94127, a critical zero-day in BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution on systems where APM is configured as an OAuth authorization server. Active exploitation was confirmed prior to the September 22 disclosure, with engineering hotfixes now available. Security teams running BIG-IP APM in OAuth server mode should treat this as an emergency patch given the pre-auth RCE impact.

Relevance score: 92.0/100

# More from September 24