Urgent.News

What's breaking now, across thousands of outlets.

Tech

F5 BIG-IP APM CVE-2026-94127: Pre-authentication RCE Zero-Day Targeting OAuth Configurations

+09:00 Source: F5 (CVE Record) Severity: critical Type: Threat Intelligence Target Period: 2026-09-23T08:14:06+09:00 to 2026-09-24T08:09:37+09:00 (Asia/Tokyo) Original Reference: BIG-IP APM OAuth vulnerability Related Sources: F5 patches…

F5 has issued a critical security advisory concerning a zero-day vulnerability, CVE-2026-94127, affecting BIG-IP APM configured with an OAuth authorization server. This pre-authentication remote code execution (RCE) flaw can be exploited by attackers remotely without authentication, potentially leading to complete takeover of the BIG-IP appliance.

The vulnerability stems from a heap-based buffer overflow in the data plane, allowing specially crafted traffic to trigger the execution of arbitrary code. F5 has confirmed active exploitation of this vulnerability, which is now listed in the Known Exploited Vulnerabilities (KEV) catalog. To mitigate the risk, F5 has released specific hotfix builds for different BIG-IP versions, and administrators are advised to apply these updates or implement temporary restrictions on OAuth authorization servers until the vulnerability is patched.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Thursday 24 September →