#1
The Hacker News
general
September 23, 2026 at 08:29 UTC
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
By [email protected] (The Hacker News)
AI Summary
F5 disclosed and patched CVE-2026-94127, a critical zero-day in BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution on systems where APM is configured as an OAuth authorization server. Active exploitation was confirmed prior to the September 22 disclosure, with engineering hotfixes now available. Security teams running BIG-IP APM in OAuth server mode should treat this as an emergency patch given the pre-auth RCE impact.
Relevance score: 92.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →