Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

F5 fixes exploited BIG-IP APM remote-code flaw

Published 23 September 2026

F5 said attackers had exploited a critical remote-code-execution flaw in its BIG-IP Access Policy Manager before the company disclosed it on September 22, and released hotfixes for affected software branches. The vulnerability applies to systems configured with both an APM access policy and an OAuth authorization-server profile; F5 said deployments using APM only as an OAuth client or resource server are not affected. Tracked as CVE-2026-94127, the flaw is a heap-based buffer overflow. F5 said specially crafted network traffic can trigger the issue and allow remote code execution on a vulnerable system. The configuration matters: having APM installed alone does not establish that a system is vulnerable. Systems operating in appliance mode can still be affected, according to the advisory. The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog on September 22. That listing reflects reported exploitation, but the available information does not identify the attackers or establish how many systems or organizations have been compromised.

0:00 / 0:00