F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
thehackernews.com Sep 24, 2026

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

AI-summarised brief · reviewed before publication

F5 disclosed a critical vulnerability (CVE‑2026‑94127) in its BIG‑IP Access Policy Manager that allows unauthenticated attackers to execute code on systems where APM functions as an OAuth authorization server. The flaw, a heap‑based buffer overflow, is present only when an access policy and OAuth profile share a virtual server, enabling remote code execution via malicious traffic. F5 released engineering hotfixes and an iRule mitigation, while CISA added the issue to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch by September 25.

💡 Why It Matters

  • · The flaw exposes a core authentication component, turning OAuth servers into potential attack vectors that bypass traditional management‑interface restrictions.
  • · Prompt remediation is essential to prevent attackers from gaining persistent, high‑privilege access to enterprise networks.