Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical F5 BIG-IP Vulnerability Under Active Exploitation

Critical F5 BIG-IP Vulnerability Under Active Exploitation

Posted on September 23, 2026 By CWS

In a critical cybersecurity development, F5 has flagged an urgent security flaw being actively targeted by hackers. This zero-day vulnerability is within the F5 BIG-IP Access Policy Manager (APM), allowing attackers to execute remote code without requiring authentication.

Understanding the Vulnerability

Identified as CVE-2026-94127, the flaw impacts virtual servers that are configured with both an APM access policy and an OAuth profile, particularly when APM functions as an OAuth Authorization Server. F5 issued advisory K000162605 on September 22, 2026, following reports of the vulnerability being exploited.

The issue is a heap-based buffer overflow, classified under CWE-122, with internal tracking ID 2524777. This flaw can be triggered by specially crafted network traffic, leading to memory corruption and arbitrary code execution on the affected BIG-IP system.

Severity and Impact

With a critical CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3, the vulnerability poses significant risks due to its low attack complexity and network reachability. It requires neither privileges nor user interaction, potentially impacting confidentiality, integrity, and availability.

Notably, the vulnerability’s impact is dependent on specific configurations, not merely the presence of APM. Systems using APM solely as an OAuth Client or Resource Server without OAuth authorization-server profiles are unaffected.

Mitigation and Response

F5 has released engineering hotfixes for affected versions, including BIG-IP APM 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3. Other BIG-IP modules and related products have been assessed as unaffected. Administrators are advised to apply these hotfixes promptly.

If immediate patching is unfeasible, F5 Support offers an iRule as a temporary mitigation measure. Organizations should also examine their systems for signs of exploitation, such as repeated OAuth authentication failures and suspicious command executions.

Urgency of Remediation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, highlighting the urgency of addressing this flaw. Although the identity of the attackers remains unknown, the threat’s scale underscores the need for swift action.

Security teams are urged to preserve logs and scrutinize any unusual activity, particularly around configurations involving OAuth Authorization Servers. Proactive threat hunting and immediate mitigation are crucial in safeguarding against this exploit.

Cyber Security News Tags:APM, BIG-IP, buffer overflow, CVE-2026-94127, Cybersecurity, F5, OAuth, remote code execution, Vulnerability, zero-day

Post navigation

Previous Post: Critical Flaw in OpenShift Allows Malicious Releases
Next Post: FBI Probes Alleged ShinyHunters Data Breach

Related Posts

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users Cyber Security News
Russian Vodka Producer Beluga Hit by Ransomware Attack Russian Vodka Producer Beluga Hit by Ransomware Attack Cyber Security News
Major AI APIs Vulnerable to Reasoning Trace Exploits Major AI APIs Vulnerable to Reasoning Trace Exploits Cyber Security News
VirtualBox 7.2.2 Released With Fix For GUI Crashes On Virtual Machines (guests) VirtualBox 7.2.2 Released With Fix For GUI Crashes On Virtual Machines (guests) Cyber Security News
Belarusian Spyware ResidentBat Targets Journalists with Precision Belarusian Spyware ResidentBat Targets Journalists with Precision Cyber Security News
New Threat: NWHStealer Uses Bun Loader and Encrypted C2 New Threat: NWHStealer Uses Bun Loader and Encrypted C2 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • FBI Probes Alleged ShinyHunters Data Breach
  • Critical F5 BIG-IP Vulnerability Under Active Exploitation
  • Critical Flaw in OpenShift Allows Malicious Releases
  • Zero-Day Tool Blocks Microsoft Defender Updates
  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • FBI Probes Alleged ShinyHunters Data Breach
  • Critical F5 BIG-IP Vulnerability Under Active Exploitation
  • Critical Flaw in OpenShift Allows Malicious Releases
  • Zero-Day Tool Blocks Microsoft Defender Updates
  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark