CyberSecurity News
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
AI summary
A critical vulnerability in F5 BIG-IP Access Policy Manager is being exploited by attackers, allowing them to execute code on a BIG-IP system without authentication. The flaw is specific to systems where APM acts as an OAuth authorization server, issuing access tokens to applications. F5 has disclosed the issue and released engineering hotfixes to address it. The vulnerability is identified as CVE-2026-94127 and was disclosed in an advisory on September 22.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

