Critical F5 BIG-IP Vulnerability Exploited, Allows Remote Code Execution
A critical vulnerability tracked as CVE-2026-94127 affects specific versions of F5's BIG-IP Access Policy Manager. The flaw is a severe heap-based buffer overflow that allows unauthenticated remote code execution on devices configured as an OAuth authorization server. F5, which rated the flaw 9.8 out of 10 in severity, issued an advisory and engineering hotfixes on September 22, 2026. The U.S. cybersecurity agency CISA added the vulnerability to its known exploited catalog on the same day, confirming active attacks.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in