Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

F5 BIG-IP APM OAuth Server Vulnerability: A Critical Security Flaw Exploited by Hackers




F5 BIG-IP APM OAuth server vulnerability: A critical security flaw exploited by hackers allowing zero-day code execution on F5 BIG-IP systems without logging in. Learn more about the vulnerability, its impact, and how to protect your organization from exploitation.

  • Critical vulnerability (CVE-2026-94127) discovered in F5 BIG-IP Access Policy Manager (APM) that allows hackers to run malicious code on F5 BIG-IP systems without logging in.
  • Severity rated as 9.8 out of 10 on CVSS v3.1 and 9.3 on CVSS v4.0, making it a critical security flaw.
  • Vulnerability affects specific versions of F5 BIG-IP APM, including branch 21.1, 17.5, and 17.1.
  • Hotfixes and iRule mitigation available to prevent exploitation.
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.
  • Importance of regular security updates and patching to prevent exploitation highlighted.
  • Need for robust incident response planning to quickly respond to security breaches.



  • F5, a leading provider of network security solutions, has recently disclosed a critical vulnerability in its BIG-IP Access Policy Manager (APM) that allows hackers to exploit a zero-day flaw and run malicious code on F5 BIG-IP systems without logging in. The vulnerability, known as CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications.

    The vulnerability is a heap-based buffer overflow that can be triggered by sending malicious traffic to the virtual server hosting the BIG-IP address that receives OAuth traffic. This allows attackers to bypass the usual security controls and gain unauthorized access to the system. The severity of the vulnerability is rated as 9.8 out of 10 on CVSS v3.1 and 9.3 on CVSS v4.0, making it a critical security flaw.

    F5 has released engineering hotfixes to address the vulnerability, and customers are advised to apply these hotfixes as soon as possible to prevent exploitation. However, in the meantime, F5 offers an iRule mitigation for affected virtual servers that can provide some level of protection. Customers can obtain this mitigation by opening a ticket with F5 support.

    The vulnerability affects specific versions of F5 BIG-IP APM, including branch 21.1, 17.5, and 17.1, and hotfix versions 21.1.0, 17.5.0, and 17.1.3. Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected by this vulnerability.

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, which provides critical alerts and advisories to federal agencies and other organizations. CISA has issued a directive to federal civilian agencies to apply F5's mitigations by September 25, 2026, to minimize the risk of exploitation.

    The attack vector for this vulnerability is unusual in that it exploits a vulnerability in the virtual server itself, rather than the BIG-IP management interface. This means that even if administrators limit access to the BIG-IP management interface, they may still be vulnerable to exploitation if the virtual server is not properly secured.

    F5 has emphasized that BIG-IP systems in Appliance mode are also vulnerable to this flaw, highlighting the importance of regular security updates and patching to prevent exploitation.

    The incident highlights the ongoing threat landscape of network security vulnerabilities and the importance of staying up-to-date with the latest security patches and best practices. Organizations that use F5 BIG-IP APM should take immediate action to apply the available hotfixes and mitigations to prevent exploitation of this critical vulnerability.

    Furthermore, the incident serves as a reminder of the importance of threat intelligence and incident response planning. Organizations should have a robust incident response plan in place to quickly respond to security breaches and minimize the impact of exploitation.

    In conclusion, the F5 BIG-IP APM OAuth server vulnerability is a critical security flaw that allows hackers to exploit a zero-day flaw and run malicious code on F5 BIG-IP systems without logging in. The vulnerability affects specific versions of F5 BIG-IP APM and has been added to CISA's KEV catalog. Organizations should take immediate action to apply the available hotfixes and mitigations to prevent exploitation and have a robust incident response plan in place to quickly respond to security breaches.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/F5-BIG-IP-APM-OAuth-Server-Vulnerability-A-Critical-Security-Flaw-Exploited-by-Hackers-ehn.shtml

  • https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html


  • Published: Wed Sep 23 04:57:56 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us