{
  "id": 9307088,
  "title": "F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers",
  "url": "https://urgent.news/2026/09/23/f5-patches-critical-big-ip-apm-zero-day-exploited-for-unauthenticated",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-23T08:29:48.000Z",
  "source": {
    "name": "The Hacker News",
    "slug": "the-hacker-news",
    "url": "https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html"
  },
  "original_language": "en",
  "account": null,
  "summary": "Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}