Back to all news
Security

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

The Hacker News·September 23, 2026·1 min read
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Attackers are exploiting a critical zero-day in F5 BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution, F5 disclosed on September 22. The flaw, CVE-2026-94127, affects systems where APM serves as an OAuth authorization server. F5 has released engineering hotfixes to address the vulnerability, which is being actively exploited.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store