Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical F5 BIG-IP APM Flaw Exploited for RCE

Critical F5 BIG-IP APM Flaw Exploited for RCE

Posted on September 23, 2026 By CWS

Security researchers have identified a significant vulnerability in F5’s BIG-IP Access Policy Manager (APM), allowing attackers to execute code without authentication. The flaw, known as CVE-2026-94127, impacts systems where APM functions as an OAuth authorization server. F5 issued an advisory on September 22, 2026, and provided engineering hotfixes to address the issue.

Understanding the Vulnerability

The flaw, characterized as a heap-based buffer overflow, is present in configurations where APM’s access policy and an OAuth authorization server profile share the same virtual server. This setup allows specific malicious traffic to lead to remote code execution. F5 assesses the vulnerability at a critical level, rating it 9.8 on the CVSS v3.1 and 9.3 on CVSS v4.0 scales.

Despite the critical nature of the flaw, limiting access to the BIG-IP management interface does not mitigate the risk. Systems operating in ‘Appliance mode’ are similarly vulnerable. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog on the same day, urging federal agencies to implement F5’s recommended mitigations by September 25.

Impact and Affected Versions

The vulnerability impacts specific versions of BIG-IP when APM acts as an OAuth authorization server. Affected versions include 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3, with specific hotfixes available for each. Systems using APM solely as an OAuth client or resource server without an authorization server profile remain unaffected.

F5 updated its records to specify that the flaw is exclusive to authorization server roles. Prior advisories from CISA and CERT-EU described the vulnerability more broadly. Notably, F5 did not evaluate versions that have reached the end of technical support, leaving their vulnerability status uncertain.

Mitigation and Response

F5’s engineering hotfixes are the primary remedy for this vulnerability. Where immediate installation is infeasible, F5 provides an iRule mitigation, accessible through their support channels. CERT-EU recommends preserving forensic evidence, applying the hotfix, and checking for possible compromises before responding to incidents.

CISA advises agencies to prioritize applying the iRule for proactive forensic analysis, followed by installing the final vendor patch. Indicators of compromise include repeated failed OAuth authentication attempts, suspicious audit log entries, and technical management module (TMM) core files signaling potential issues.

While these measures aim to safeguard affected systems, it remains unclear if the hotfix can eliminate existing unauthorized access. Organizations are urged to remain vigilant and ensure their systems are updated promptly.

The Hacker News Tags:APM, BIG-IP, CERT-EU, CISA, Cybersecurity, F5, Hotfix, network security, OAuth, RCE, Vulnerability

Post navigation

Previous Post: F5 BIG-IP Zero-Day Vulnerability Exploited
Next Post: Arista Releases Urgent Patch for Critical VCO Vulnerability

Related Posts

Understanding Identity-Based Cyber Attacks and Defense Understanding Identity-Based Cyber Attacks and Defense The Hacker News
Browser Extension Risks AI Assistant Security Browser Extension Risks AI Assistant Security The Hacker News
Google Eliminates AI Workflows Over GitHub Security Flaw Google Eliminates AI Workflows Over GitHub Security Flaw The Hacker News
Hackers Use Fake VPN and Browser NSIS Installers to Deliver Winos 4.0 Malware Hackers Use Fake VPN and Browser NSIS Installers to Deliver Winos 4.0 Malware The Hacker News
Phishing Risks and Cyber Threats: Top Stories of the Week Phishing Risks and Cyber Threats: Top Stories of the Week The Hacker News
How Attackers Exploit SOC Workloads Beyond Phishing Emails How Attackers Exploit SOC Workloads Beyond Phishing Emails The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Cyberattacks: New Era of Fraud and Trust Misuse
  • ShinyHunters Allegedly Breach FBI Systems, Demand Retraction
  • Chinese Hackers Target Chrome-Windows with Zero-Day Exploits
  • Leading Decentralized Identity Solutions for 2026
  • Arista Releases Urgent Patch for Critical VCO Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Cyberattacks: New Era of Fraud and Trust Misuse
  • ShinyHunters Allegedly Breach FBI Systems, Demand Retraction
  • Chinese Hackers Target Chrome-Windows with Zero-Day Exploits
  • Leading Decentralized Identity Solutions for 2026
  • Arista Releases Urgent Patch for Critical VCO Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark