Search
Find merged stories by title or summary.
F5 fixes actively exploited zero-day flaw in BIG-IP APM
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch became available. BIG-IP APM is a software component in F5’s BIG-IP hardware platform that enables companies to control access to internal network resources. APM performs various client-side checks and handles authorization and authentication, along with providing VPN connectivity for remote users. The flaw, tracked as CVE-2026-94127, is described as a heap-based buffer overflow and is rated 9. 8 on the CVSS scale. The vulnerability impacts the BIG-IP system when configured in appliance mode as well but can be exploited only when both APM and an OAuth authorization server profile are configured.
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability • CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability • CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability • CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks and run their own code on the gateway.
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild. The flaw can allow an unauthenticated attacker to execute arbitrary code on a vulnerable BIG-IP system. F5 disclosed the issue on September 22 and confirmed that exploitation had already been observed. The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server. More specifically, the vulnerable configuration is one in which APM operates as an OAuth Authorization Server. Systems using APM only as an OAuth Client or Resource Server are not affected.
CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM
Overview On September 22, 2026, F5 published a security advisory for CVE-2026-94127 , a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3. 1 score of 9. 8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic. BIG-IP APM provides identity-aware access control for applications and other corporate resources and can integrate with authentication technologies including OAuth, OpenID Connect, and SAML. CVE-2026-94127 is not exposed in a default configuration: exploitation requires a BIG-IP virtual server with both an APM access policy and an OAuth profile configured.
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.
F5 BIG-IP APM Zero-Day CVE-2026-94127 Actively Exploited for RCE
F5 BIG-IP APM deployments configured as OAuth authorization servers are affected by CVE-2026-94127, a critical heap-based buffer overflow that can allow unauthenticated remote code execution and is being exploited in the wild. The post F5 BIG-IP APM Zero-Day CVE-2026-94127 Actively Exploited for RCE appeared first on CyberUpdates365 • Latest Cybersecurity News & Vulnerabilities .
CVE-2026-94127 Detail - nvd.nist.gov
CVE-2026-94127 Detail nvd. nist. gov
CVE-2026-94127 - BIG-IP APM OAuth vulnerability
CVE ID : CVE-2026-94127 Published : Sept. 22, 2026, 2:17 p. m. • 41 minutes ago Description : When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Severity: 9.8
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability • CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability • CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability • CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
[CISA] CVE-2026-94127 - Confirmed Exploitation
CVE-2026-94127 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-09-22 00:00 UTC Evidence Sources: 1 First Seen: 2026-09-22 Asserted: 2026-09-22
You've reached the end of current stories for this search.
