F5 Patches Critical BIG-IP APM Zero-Day Exploited for… | HappeningNow.news

Cybersecurity

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.

Source Summary Published 1h 05m ago Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views New Be the first to read
Brief read Under 1 min brief 47 words

Summary

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications.

Read original at The Hackernews

Coverage Context

Part of Oauth coverage 37 tracked stories

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page