Post
securityrss.ai
securityrss.bsky.social
did:plc:geidqukzen75knciqkq77vgq
F5 has reported a critical zero-day vulnerability (CVE-2026-94127) in BIG-IP Access Policy Manager, allowing remote code execution without authentication. The flaw, a heap-based buffer overflow, affects specific configurations using APM as an OAuth Authorization Server. It has a CVSS score of 9.8.
https://cybersecuritynews.com/f5-big-ip-oauth-server-0-day-flaw/
2026-09-23T18:49:28.873Z