TechWave AI Pulse Signal over noise
UGLY SECURITY GLOBAL

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authori

The Hacker News 2 newsrooms Wed, 23 Sep 2026 08:29
Read the original at The Hacker News ↗

Also reported by 1 other newsroom