F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Overview
F5 Networks has reported a serious vulnerability in its BIG-IP Access Policy Manager (APM) that allows attackers to execute arbitrary code on systems without authentication. This flaw, identified as CVE-2026-94127, specifically impacts systems where APM functions as an OAuth authorization server, which is responsible for generating access tokens for applications. F5 disclosed this issue on September 22, 2023, and has since released hotfixes to address the vulnerability. Organizations using affected versions of BIG-IP APM are urged to apply these updates promptly to protect against potential exploitation. The situation is critical as attackers are actively taking advantage of this flaw, posing significant risks to the security of OAuth servers.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: F5 BIG-IP Access Policy Manager (APM) systems configured as OAuth authorization servers.
- Action Required: F5 has released engineering hotfixes to address the vulnerability.
- Timeline: Disclosed on September 22, 2023
Original Article Summary
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.
Impact
F5 BIG-IP Access Policy Manager (APM) systems configured as OAuth authorization servers.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Disclosed on September 22, 2023
Remediation
F5 has released engineering hotfixes to address the vulnerability. Users should apply these hotfixes to their affected BIG-IP APM systems immediately.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Zero-day, Vulnerability, and 3 more.