Close Menu
NCIJ Network NCIJ Network
    What's Hot

    US court rules against Kalshi, says states can regulate prediction markets | Courts News

    September 26, 2026

    Special agents blood and urine test results stolen in FBI hack

    September 26, 2026

    Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

    September 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • US court rules against Kalshi, says states can regulate prediction markets | Courts News
    • Special agents blood and urine test results stolen in FBI hack
    • Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
    • Live updates: Bitcoin moves to $84,000, oil slides on latest report of Middle East progress
    • Why Viking museums still can’t escape the warrior myth
    • Classy or classist? How bare nails became a hot issue
    • Global coral reefs get less time to recover as oceans heat up, report finds
    • ‘Furious’ Captures Women’s Choked Rage
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 26
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 23, 2026Vulnerability / Network Security

    Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.

    The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.

    APM is the BIG-IP module that controls how users reach an organization’s applications and networks. The vulnerable setup has an APM access policy and an OAuth authorization server profile on the same virtual server, which hosts the BIG-IP address that receives the OAuth traffic. Specific malicious traffic sent to that virtual server can lead to remote code execution.

    The flaw is a heap-based buffer overflow. F5 rates it 9.8 out of 10 on CVSS v3.1 and 9.3 on CVSS v4.0.

    Because the malicious traffic goes to the virtual server itself, limiting access to the BIG-IP management interface does not protect against this flaw. BIG-IP systems in Appliance mode are also vulnerable.

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 22. It gave federal civilian agencies until September 25 to apply F5’s mitigations, under a directive CISA issued in June.

    Cybersecurity

    F5’s CVE record and CISA’s KEV entry do not say how many systems were attacked, who the attackers are, or which organizations were targeted.

    Who Is Affected

    For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:

    Branch Affected versions Fixed in
    21.1 21.1.0, before the hotfix Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
    17.5 17.5.0 to 17.5.1, before the hotfix Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
    17.1 17.1.0 to 17.1.3, before the hotfix Hotfix-BIGIP-17.1.3.5.0.41.14-ENG

    Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.

    F5 updated its CVE record at 00:45 UTC on September 23 to say the flaw is present only in the authorization server role. CISA’s KEV entry and an advisory from CERT-EU, the cybersecurity service for EU institutions, were published before that change. Both describe the condition more broadly, as an access policy and an OAuth profile on a virtual server.

    In F5’s configuration guide for APM 17.1, 17.5 and 21.0, the authorization server’s OAuth profile is created under Access > Federation > OAuth Authorization Server > OAuth Profile. It is then selected in an access profile attached to the virtual server. A virtual server set up this way matches the condition F5 describes.

    F5 did not evaluate versions that have reached End of Technical Support, so their status is unknown rather than safe.

    Another APM flaw, CVE-2025-53521, was added to CISA’s KEV catalog in March. Its fixes for the 17.1 and 17.5 branches, 17.1.3 and 17.5.1.3, fall inside the affected ranges above. A system updated to either build still needs the new hotfix if APM acts as an OAuth authorization server on it.

    What to Do Now

    F5’s fix is the engineering hotfix listed for each branch in the table. When the hotfix cannot be installed immediately, F5 offers an iRule mitigation for the affected virtual server. Customers get it by opening a ticket with F5 support.

    CERT-EU advises preserving forensic evidence first, applying the hotfix, checking for signs of compromise, and starting incident response if any are found.

    Cybersecurity

    CISA told agencies to apply the iRule first “to allow for proactive forensic triage,” and then to “install the final vendor patch as soon as possible.”

    Checking for Compromise

    The signs below are F5’s, as listed in CERT-EU’s advisory. The combination that should lead to a human review of the system is repeated OAuth authentication failures, followed by suspicious commands, followed by a TMM SIGABRT shortly after.

    • APM log: repeated failed UserInfo requests in /var/log/apm with the error description “The access token is invalid.” Look especially for 10 or more requests from a single IP address within a short time.
    • OAuth counter: an unexplained rise in total_failed when running tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed.
    • Audit log: suspicious commands in /var/log/audit around the times of those failures.
    • TMM core files: not a sign on their own, but worth investigating. F5 has seen TMM enter a loop, causing the SOD daemon to send a SIGABRT.

    F5’s CVE record and the CISA and CERT-EU advisories do not say whether installing the hotfix removes access that an attacker already has.

    APM BIGIP critical Exploited OAuth Patches RCE Servers unauthenticated ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

    Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

    TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    Elementor WordPress flaw lets attackers create admin accounts

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    US court rules against Kalshi, says states can regulate prediction markets | Courts News

    September 26, 2026

    Special agents blood and urine test results stolen in FBI hack

    September 26, 2026

    Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

    September 26, 2026

    Live updates: Bitcoin moves to $84,000, oil slides on latest report of Middle East progress

    September 26, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    US court rules against Kalshi, says states can regulate prediction markets | Courts News

    September 26, 2026

    Special agents blood and urine test results stolen in FBI hack

    September 26, 2026

    Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

    September 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.