F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
- ID
- 27632
- Status
- summarized
- Published
- 23 Sep 2026, 4:29 PM
- Fetched
- 23 Sep 2026, 5:39 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 23 Sep 2026, 5:40 PM
- Tags
- Audience
- developersdatabase_learnerssaas_founders
What happened
F5 disclosed CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow in BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution when APM is configured as an OAuth authorization server on the same virtual server as an access policy. CISA added it to its Known Exploited Vulnerabilities catalog on September 22, requiring federal agencies to apply mitigations by September 25. Engineering hotfixes are available for branches 21.1, 17.5, and 17.1; systems using APM only as an OAuth client or resource server are not affected.
Why it matters
If your organization runs F5 BIG-IP with APM in the OAuth authorization server role on the same virtual server as an access policy, you need to apply the branch-specific engineering hotfix immediately—this is actively exploited and limiting access to the management interface does not help. Malaysian enterprises, telcos, or government agencies using BIG-IP for OAuth should check their APM configuration now to confirm whether they run the authorization server profile.
Discussion angle
How many Malaysian enterprises and telcos still run F5 BIG-IP as their OAuth/identity gateway, and what does patching logistics look like when the fix is an engineering hotfix rather than a full release?