AI Weekly Malaysia

Back to items Summaries

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

ID
27632
Status
summarized
Published
23 Sep 2026, 4:29 PM
Fetched
23 Sep 2026, 5:39 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.5
Created
23 Sep 2026, 5:40 PM
Tags
Audience
developersdatabase_learnerssaas_founders

What happened

F5 disclosed CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow in BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution when APM is configured as an OAuth authorization server on the same virtual server as an access policy. CISA added it to its Known Exploited Vulnerabilities catalog on September 22, requiring federal agencies to apply mitigations by September 25. Engineering hotfixes are available for branches 21.1, 17.5, and 17.1; systems using APM only as an OAuth client or resource server are not affected.

Why it matters

If your organization runs F5 BIG-IP with APM in the OAuth authorization server role on the same virtual server as an access policy, you need to apply the branch-specific engineering hotfix immediately—this is actively exploited and limiting access to the management interface does not help. Malaysian enterprises, telcos, or government agencies using BIG-IP for OAuth should check their APM configuration now to confirm whether they run the authorization server profile.

Discussion angle

How many Malaysian enterprises and telcos still run F5 BIG-IP as their OAuth/identity gateway, and what does patching logistics look like when the fix is an engineering hotfix rather than a full release?

Top