bleeping-computer · Crawled Sep 23, 2026

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

Read original article ↗

AI Summary

F5 has released security updates to address a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP APM (Access Policy Manager) product that is being actively exploited in remote code execution attacks. The vulnerability affects systems configured as an OAuth Authorization Server with specific access policies and OAuth profiles on a virtual server. Exploitation can lead to remote code execution, and F5 has confirmed active attacks. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies to remediate by a specified deadline.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.