{
  "id": 9410668,
  "title": "Someone's attacking a critical 0-day RCE in F5 BIG-IP APM",
  "url": "https://urgent.news/2026/09/23/someones-attacking-a-critical-0-day-rce-in-f5-big-ip-apm",
  "topic": "science",
  "section": "Science",
  "published": "2026-09-23T18:09:28.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/23/someones-attacking-a-critical-0-day-rce-in-f5-big-ip-apm/5298659"
  },
  "original_language": "en",
  "account": "F5 has patched a critical zero-day vulnerability in its BIG-IP Access Policy Manager (APM), which attackers were exploiting to execute malicious code remotely. This flaw, identified as CVE-2026-94127, is a heap-based buffer overflow affecting systems configured as OAuth Authorization Servers with specific access policies and OAuth profiles. The vulnerability was rated with a critical 9.3 CVSS v4.0 score by F5. F5 received an alert from the US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday, urging federal agencies to apply the patches by Friday. This development follows a year ago when F5 and CISA warned of a potential intrusion by sophisticated nation-state hackers who stole BIG-IP source code, zero-day vulnerability details, and customer configurations.",
  "summary": "Good news: there's a patch. Bad news: both CISA and F5 warn that it's under active exploitation",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Someone's attacking a critical 0-day RCE in F5 BIG-IP APM",
        "url": "https://urgent.news/2026/09/23/someones-attacking-a-critical-0-day-rce-in-f5-big-ip-apm-9413684",
        "published": "2026-09-23T18:09:28.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}