hacker-news · Crawled Sep 23, 2026
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Read original article ↗AI Summary
F5 has patched a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution on systems where APM is configured as an OAuth authorization server. The vulnerability is a heap-based buffer overflow with a CVSS v3.1 score of 9.8, and it is actively exploited in the wild. Malicious traffic targeting the virtual server can trigger remote code execution, bypassing protections on the management interface. The U.S. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and mandated federal agencies to apply mitigations within three days.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.