F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
What it means
F5 ha rilevato un bug critico (CVE-2026-94127) in BIG-IP APM, che permette esecuzione remota di codice senza autenticazione. L'errore è un overflow di buffer heap e colpisce sistemi in cui APM funge da server OAuth. F5 ha rilasciato hotfix e CISA ha incluso la vulnerabilità nel KEV. L'attacco richiede traffico malizioso inviato a un server virtuale configurato specificamente.
Why it matters
Per le PMI italiane, la vulnerabilità rappresenta un rischio elevato per la sicurezza delle applicazioni e delle reti, specialmente se APM è configurato come server OAuth. L'accesso non autorizzato potrebbe portare a compromissioni critiche e perdita di dati sensibili.
Recommended actions
- Apply the engineering hotfix for affected versions of BIG-IP APM
- Install the iRule mitigation if the hotfix cannot be applied immediately
- Monitor for repeated OAuth authentication failures and suspicious commands in logs
- Check for TMM SIGABRT and core files indicating a loop
- Preserve forensic evidence and initiate incident response if signs of compromise are found
- Review and update access policies for OAuth servers to limit exposure
Potential operational benefits
- Riduzione della superficie esposta per attacchi non autorizzati
- Miglioramento della rilevazione e risposta agli incidenti
- Protezione contro esecuzioni remote di codice non autorizzate
- Maggiore controllo sulla configurazione e accesso ai sistemi
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.
- Source
- The Hacker News
- Publishing entity
- The Hacker News
- Entity type
- editorial osint
- Area
- Global
- Original language
- en · translation in preparation
- Publication
- 23/09/2026 10:29
- MITRE ATT&CK
- T1562, T1059.001, T1486
- CVE
- CVE-2026-94127
- Classification
- Critical
Affected products and versions
The collector will check NVD and the available official vendor advisories.