Urgent.News

What's breaking now, across thousands of outlets.

Tech

F5 BIG-IP APM CVE-2026-94127: an unauthenticated RCE that a hardening setting does not stop

F5 BIG-IP APM CVE-2026-94127: an unauthenticated RCE that a hardening setting does not stop A load balancer can be an attack surface, not only a traffic cop. CVE-2026-94127 in F5 BIG-IP Access Policy Manager (APM) shows why that distinction matters at the edge of the network. What the vulnerability is F5 published advisory K000162605 for CVE-2026-94127 on 2026-09-22, and CISA added the CVE to its…

The F5 BIG-IP Access Policy Manager (APM) has a critical vulnerability, CVE-2026-94127, which allows unauthenticated remote code execution (RCE) via a heap-based buffer overflow in the data plane path handling OAuth traffic. This flaw does not require any credentials or user interaction and affects specific BIG-IP deployments where APM is used as an OAuth client or resource server.

F5 has released hotfixes for affected versions, but the vulnerability cannot be mitigated by Appliance mode or restricting the management interface. Enterprises should prioritize identifying and patching affected BIG-IP APM virtual servers that combine an access policy with an OAuth authorization server profile and consider inventorying and securing these instances as a top priority.

Brief written by urgent.news from Dev.to's own syndicated text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

A No-Nonsense Cloud Landing Zone Checklist (Azure, AWS, Google Cloud)

If you've ever been handed a brand-new Azure subscription, AWS account or Google Cloud project and told to "just get something running," you already know the real problem isn't the workload.

  • Cloud landing zone is foundational platform for secure workload launch in Azure, AWS, Google Cloud
  • Key components include identity management, policies for security enforcement, centralized logging
  • Define identity provider, enforce MFA, avoid workloads in management account before deployment

async job processing: Optimize Long-Running Tasks for 2026

How async job processing moves long-running agent work out of HTTP requests Long-running agent work looks fine right up until it hits real traffic. Then requests start hanging, workers stay busy too long, retries get messy, and users have no clear idea whether anything is still happening.

More from Thursday 1 October →