Story thread · 8 reports / 8 sources
F5 fixes actively exploited zero-day flaw in BIG-IP APM
networkworld.com · 6h

How the coverage leans
Across 8 sources · syndicated copies counted once
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch became available. BIG-IP APM is a software component in F5’s BIG-IP hardware platform that enables companies to control access to internal network resources. APM performs various client-side checks and handles authorization and authentication, along with providing VPN connectivity for remote users. The flaw, tracked as CVE-2026-94127, is described as a heap-based buffer overflow and is rated 9.8 on the CVSS scale. The vulnerability impacts the BIG-IP system when configured in appliance mode as well but can be exploited only when both APM and an OAuth authorization server profile are configured. Deployments using APM only as an OAuth client or resource server are not affected, F5 said in its advisory . The compa
First report: The OAuth Profile Is the Door: F5 BIG-IP APM’s Heap Overflow Turns a Network Security Appliance Into an Unauthenticated Entry Point — forkast.news, 1d
The coverage
- Someone's attacking a critical 0-day RCE in F5 BIG-IP APM
theregister.com · 9h
- Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
helpnetsecurity.com · 17h
The conversation · 0
Sign in to join the conversation.
No comments yet — start the thread.