Smart news for curious minds.

Nerd News Network
Networking

F5 fixes actively exploited zero-day flaw in BIG-IP APM

Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday.

Lead image for “F5 fixes actively exploited zero-day flaw in BIG-IP APM”.
Image: Network World
Share

Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday.

The short version

  • The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch became available.
  • BIG-IP APM is a software component in F5’s BIG-IP hardware platform that enables companies to control access to internal network resources.
  • APM performs various client-side checks and handles authorization and authentication, along with providing VPN connectivity for remote users.

What happened

The flaw, tracked as CVE-2026-94127, is described as a heap-based buffer overflow and is rated 9.8 on the CVSS scale. The vulnerability impacts the BIG-IP system when configured in appliance mode as well but can be exploited only when both APM and an OAuth authorization server profile are configured.

Why it matters

Deployments using APM only as an OAuth client or resource server are not affected, F5 said in its advisory .

Summary by Nerd News Network. Read the full article at Network World via the links above and below.

Share