Interestana
Home/News/F5 Patches Critical BIG-IP APM Zero-Day Exploited for RCE
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

F5 Patches Critical BIG-IP APM Zero-Day Exploited for RCE

F5 Patches Critical BIG-IP APM Zero-Day Exploited for RCE

F5 Networks has released engineering hotfixes to address a critical zero-day vulnerability in its BIG-IP Access Policy Manager (APM) product. The flaw, identified as CVE-2026-94127, allows attackers to achieve unauthenticated remote code execution (RCE) on affected BIG-IP systems. This vulnerability specifically impacts BIG-IP instances configured to function as OAuth authorization servers, a role where the APM component is responsible for issuing access tokens to various applications. The exploitation of this vulnerability does not require any form of authentication, meaning an attacker could gain unauthorized control of the system without needing valid user credentials.

F5 disclosed the existence and details of this critical flaw in an official advisory published on September 22. The company has stated that the vulnerability affects only those BIG-IP systems where the APM module is actively serving as an OAuth authorization server. This configuration is common in environments that use BIG-IP for managing access to applications and services through token-based authentication protocols like OAuth. The ability to execute arbitrary code on a network device without prior authentication represents a significant security risk, potentially allowing attackers to compromise sensitive data, disrupt services, or use the device as a pivot point for further network intrusions.

While F5 has provided engineering hotfixes, the company's advisory emphasizes that these are temporary solutions. Customers are strongly advised to apply these patches as soon as possible to mitigate the risk of exploitation. The disclosure of this vulnerability as a "zero-day" indicates that it was actively being exploited in the wild before F5 became aware of it and had a chance to develop a permanent fix. The specific details of the exploitation methods and the extent of any actual breaches are not fully detailed in the initial advisory, but the potential for severe impact is clear given the nature of RCE vulnerabilities.

The BIG-IP platform from F5 is a widely used application delivery and security solution that provides services such as load balancing, web application firewalling, and access management. The APM module, in particular, is crucial for securing access to applications and managing user identities. A vulnerability in such a critical component, especially one that allows for unauthenticated RCE, poses a substantial threat to organizations relying on F5's products for their network security infrastructure. Users of BIG-IP APM are urged to consult F5's official security advisories for the most up-to-date information and guidance on applying the necessary patches and implementing any recommended workarounds.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next