ESPN😡 CFB Bottom 10: NC State had a really bad dayESPN DeportesGiants: Dart será operado y no volverá este añoThe Jerusalem PostTurkey’s Bashiqa base handover marks a new chapter for post-ISIS Iraq - analysisInquirerHighlights: Day 29 of Sara Duterte impeachment trial | Sept. 23, 2026Antara NewsIndonesia to fund free public schools from existing 2027 budgetTechCrunchAnthropic says its biology lab has already found something bigNHK 社会台風25号 10人死亡4人不明 北印旛沼周辺で浸水被害 復旧急ぐCBS NewsHarvey Weinstein sentenced to 15 years in New York sexual assault caseMexico News DailyThe MND Mexico Well-being Series, Part 1: Health and healthcareStraits Times SportNew College Swimming League dives into inaugural season with eye on wider audienceRolling StoneNew Details Emerge in Hayden Panettiere Death, Report DetailsSDP Espectáculos¿Quién es Mónica León? esposa de Jesse Huerta
The Daily Newsstand · Free, Always
Wednesday, September 23, 2026

Someone's attacking a critical 0-day RCE in F5 BIG-IP APM

Translate

Good news: there's a patch. Bad news: both CISA and F5 warn that it's under active exploitation

F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code.

BIG-IP APM is a centralized access management and security proxy that allows users to connect to enterprise networks, applications, APIs, and cloud services via a single login. 

The flaw, tracked as CVE-2026-94127, is a heap-based buffer overflow that affects BIG-IP APM systems configured as an OAuth Authorization Server, with an access policy and OAuth profile on the same virtual server. It received a critical 9.3 CVSS v4.0 score - so patch now.

REG AD

“We have learned that this vulnerability has been exploited,” F5 said in a Tuesday security advisory.

REG AD

F5 did not immediately respond to our questions, including how many systems have been compromised, and whether criminals are abusing the vulnerability to deploy ransomware.

Also on Tuesday, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, and gave federal agencies a Friday deadline to apply patches.

This warning comes about a year after F5 and CISA warned “highly sophisticated nation-state" hackers broke into the vendor’s network and stole BIG-IP source code, zero-day vulnerability details, and customer configuration data belonging to some users. 

The attack posed an "imminent risk" to federal agencies, US cybersecurity officials said at the time. The US Justice Department allowed F5 to delay disclosing the intrusion after determining that delayed public disclosure was warranted. This only happens if public disclosure poses a substantial risk to national security or public safety.

Neither the feds nor private researchers have publicly attributed the intrusion to a particular group or country, but a year earlier Google's Mandiant threat hunters linked exploitation of the critical F5 BIG-IP flaw CVE-2023-46747 to UNC5174, an access broker it assessed with moderate confidence as operating from China. The group attempted to sell access to US defense contractor appliances and UK government entities.®

View the original on The Register

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.