F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Reported exploitedBIG-IP Access Policy ManagerOur summary
F5 has released engineering hotfixes for CVE-2026-94127, an exploited heap-based buffer overflow in BIG-IP Access Policy Manager when it operates as an OAuth authorization server. Unauthenticated attackers can send crafted traffic to an affected virtual server and execute code; impacted releases are 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 before their respective hotfixes. Organizations should install the applicable F5 hotfix, or obtain F5's iRule mitigation while investigating for compromise.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.