F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.

The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial

LG smart TVs caught logging audio with screen off and snooping on local devices

LG smart TVs caught logging audio with screen off and snooping on local devices Source: Hacker News

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and