Hackers Exploiting F5 BIG-IP OAuth Server 0-day Flaw to Gain Remote Code Execution

F5 has warned that hackers are actively exploiting a critical zero-day vulnerability in BIG-IP Access Policy Manager (APM) deployments to execute code remotely without authentication. Tracked as CVE-2026-94127, the flaw affects virtual servers configured with both an APM access policy and an OAuth profile, specifically where APM operates as an OAuth Authorization Server. F5 published […]

This article has been indexed from Cyber Security News

Read the original article: