Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical F5 BIG-IP APM Flaw Exploited for RCE

Critical F5 BIG-IP APM Flaw Exploited for RCE

Posted on September 23, 2026 By CWS

Security researchers have identified a significant vulnerability in F5’s BIG-IP Access Policy Manager (APM), allowing attackers to execute code without authentication. The flaw, known as CVE-2026-94127, impacts systems where APM functions as an OAuth authorization server. F5 issued an advisory on September 22, 2026, and provided engineering hotfixes to address the issue.

Understanding the Vulnerability

The flaw, characterized as a heap-based buffer overflow, is present in configurations where APM’s access policy and an OAuth authorization server profile share the same virtual server. This setup allows specific malicious traffic to lead to remote code execution. F5 assesses the vulnerability at a critical level, rating it 9.8 on the CVSS v3.1 and 9.3 on CVSS v4.0 scales.

Despite the critical nature of the flaw, limiting access to the BIG-IP management interface does not mitigate the risk. Systems operating in ‘Appliance mode’ are similarly vulnerable. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog on the same day, urging federal agencies to implement F5’s recommended mitigations by September 25.

Impact and Affected Versions

The vulnerability impacts specific versions of BIG-IP when APM acts as an OAuth authorization server. Affected versions include 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3, with specific hotfixes available for each. Systems using APM solely as an OAuth client or resource server without an authorization server profile remain unaffected.

F5 updated its records to specify that the flaw is exclusive to authorization server roles. Prior advisories from CISA and CERT-EU described the vulnerability more broadly. Notably, F5 did not evaluate versions that have reached the end of technical support, leaving their vulnerability status uncertain.

Mitigation and Response

F5’s engineering hotfixes are the primary remedy for this vulnerability. Where immediate installation is infeasible, F5 provides an iRule mitigation, accessible through their support channels. CERT-EU recommends preserving forensic evidence, applying the hotfix, and checking for possible compromises before responding to incidents.

CISA advises agencies to prioritize applying the iRule for proactive forensic analysis, followed by installing the final vendor patch. Indicators of compromise include repeated failed OAuth authentication attempts, suspicious audit log entries, and technical management module (TMM) core files signaling potential issues.

While these measures aim to safeguard affected systems, it remains unclear if the hotfix can eliminate existing unauthorized access. Organizations are urged to remain vigilant and ensure their systems are updated promptly.

The Hacker News Tags:APM, BIG-IP, CERT-EU, CISA, Cybersecurity, F5, Hotfix, network security, OAuth, RCE, Vulnerability

Post navigation

Previous Post: F5 BIG-IP Zero-Day Vulnerability Exploited
Next Post: Arista Releases Urgent Patch for Critical VCO Vulnerability

Related Posts

Exposure Assessment Platforms Signal a Shift in Focus Exposure Assessment Platforms Signal a Shift in Focus The Hacker News
CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers The Hacker News
Global Cyber Threats Target Defense Sector Amid Rising Tensions Global Cyber Threats Target Defense Sector Amid Rising Tensions The Hacker News
Uncover Gaps in Automated Pentesting with Expert Insights Uncover Gaps in Automated Pentesting with Expert Insights The Hacker News
Ghost Campaign Targets Crypto Wallets via Malicious npm Packages Ghost Campaign Targets Crypto Wallets via Malicious npm Packages The Hacker News
Critical Telnetd Security Flaw Allows Remote Code Execution Critical Telnetd Security Flaw Allows Remote Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Leading Decentralized Identity Solutions for 2026
  • Arista Releases Urgent Patch for Critical VCO Vulnerability
  • Critical F5 BIG-IP APM Flaw Exploited for RCE
  • F5 BIG-IP Zero-Day Vulnerability Exploited
  • Next.js Vulnerability Allows Server Code Execution via SVG

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Leading Decentralized Identity Solutions for 2026
  • Arista Releases Urgent Patch for Critical VCO Vulnerability
  • Critical F5 BIG-IP APM Flaw Exploited for RCE
  • F5 BIG-IP Zero-Day Vulnerability Exploited
  • Next.js Vulnerability Allows Server Code Execution via SVG

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark