EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 95/100

F5 ha rilevato un bug critico (CVE-2026-94127) in BIG-IP APM, che permette esecuzione remota di codice senza autenticazione. L'errore è un overflow di buffer heap e colpisce sistemi in cui APM funge da server OAuth. F5 ha rilasciato hotfix e CISA ha incluso la vulnerabilità nel KEV. L'attacco richiede traffico malizioso inviato a un server virtuale configurato specificamente.

Why it matters

Per le PMI italiane, la vulnerabilità rappresenta un rischio elevato per la sicurezza delle applicazioni e delle reti, specialmente se APM è configurato come server OAuth. L'accesso non autorizzato potrebbe portare a compromissioni critiche e perdita di dati sensibili.

Potential operational benefits

  • Riduzione della superficie esposta per attacchi non autorizzati
  • Miglioramento della rilevazione e risposta agli incidenti
  • Protezione contro esecuzioni remote di codice non autorizzate
  • Maggiore controllo sulla configurazione e accesso ai sistemi
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementEDR / XDRFirewall NGFW / IPSMonitoraggio / SIEMSegmentazione di rete
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
23/09/2026 10:29
MITRE ATT&CK
T1562, T1059.001, T1486
CVE
CVE-2026-94127
Classification
Critical
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source