CVE Tools

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

The Hacker NewsBy The Hacker News

Reported exploitedBIG-IP Access Policy Manager

Our summary

F5 has released engineering hotfixes for CVE-2026-94127, an exploited heap-based buffer overflow in BIG-IP Access Policy Manager when it operates as an OAuth authorization server. Unauthenticated attackers can send crafted traffic to an affected virtual server and execute code; impacted releases are 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 before their respective hotfixes. Organizations should install the applicable F5 hotfix, or obtain F5's iRule mitigation while investigating for compromise.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store