← nejvýznamnější zprávy · všechny zprávy

SPOJENO AI KEV ✓ EPSS 0.01

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. [...]

Číst originál na BleepingComputer →

12 zpráv z 11 zdrojů · první 22. 9. 02:00 · poslední 23. 9. 13:59 CZ · EN/orig

F5 RO SE US HU FR CA EU IT NL

tg: zneužíváno tg: zranitelnost

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-94127 9.8 3.1 · f5 9.3 4.0 · f5 KEV ✓ 0.01

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.

Jak se o tom psalo 12

  1. · DNSC Rumunsko RO

    ALERTĂ: Vulnerabilitate critică exploatată activ în F5 BIG-IP APM

    DESCRIERE CVE-2026-94127 este o vulnerabilitate critică identificată în componenta APM OAut...

  2. · CERT-SE SE

    Information om kritisk sårbarhet i F5 BIG-IP APM

    F5 har publicerat information om en kritisk sårbarhet, CVE-2026-94127, i BIG-IP APM. Sårbarheten kan resultera i att en oautentiserad angripare kan fjärrexekvera godtycklig kod.

  3. · Rapid7 US

    CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

    OverviewOn September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.BIG-IP APM provides identity-aware access control for applications and other corporate resources…

  4. · NKI Maďarsko HU

    Riasztás az F5 BIG-IP APM rendszert érintő CVE-2026-94127 sérülékenységről

    A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a BIG-IP Access Policy Manager-t (APM) érintő CVE-2026-94127 azonosítón nyomon követett, kritikus, nulladik napi sérülékenység kapcsán. A sérülékenység egy heap-alapú puffertúlcsordulás, amely hitelesítés nélküli távoli kódfuttatást tehet lehetővé az érintett BIG-IP rendszereken. A sebezhetőség a CVSS v3.1 pontozási rendszer alapján 9,8-as súlyossági besorolást kapott. Ha egy […]

  5. · BleepingComputer US nadpis události

    F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

    F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. [...]

  6. · CERT-FR – avis FR

    Vulnérabilité dans F5 BIG-IP (23 septembre 2026)

    Une vulnérabilité a été découverte dans F5 BIG-IP. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. L'éditeur indique que la vulnérabilité CVE-2026-94127 est activement exploitée. Des indicateurs de compromission sont disponibles dans l'avis de l'éditeur.

  7. · Cyber Centre Kanada CA

    AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127

    Number: AL26-022Date: September 22, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian…

  8. · CERT-EU EU

    2026-013: Critical Vulnerability in F5 BIG-IP APM

    On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking appropriate actions as soon as possible.

  9. · Cyber Centre Kanada CA

    F5 security advisory (AV26-949)

    Serial number: AV26-949Date: September 22, 2026 As of September 22, 2026, F5 is affected by a vulnerability in the following product: BIG-IP Versions 21.1.0 to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG Versions 17.5.0 to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG Versions 17.1.0 to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG F5 has reported that CVE-2026-94127 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they…

  10. · CSIRT Itálie (ACN) IT

    F5 BIG-IP: rilevato sfruttamento in rete della CVE-2026-94127

    Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-94127, presente in BIG-IP APM. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a utenti malintenzionati remoti di eseguire codice arbitrario sui sistemi interessati.

  11. · NCSC-NL NL

    NCSC-2026-0386 [1.00] [H/H] Kwetsbaarheid verholpen in F5 Networks BIG-IP Access Policy Manager

    F5 Networks heeft een kwetsbaarheid verholpen in BIG-IP Access Policy Manager (APM). De kwetsbaarheid stelt een ongeauthenticeerde kwaadwillende in staat om malafide code uit te voeren. Hiertoe dient de kwaadwillende malafide netwerkverkeer naar het kwetsbare systeem te versturen. BIG-IP APM-systemen zijn alleen kwetsbaar wanneer een access policy en een OAuth-profiel op de virtuele server zijn geconfigureerd. F5 Networks geeft aan dat het een zeroday-kwetsbaarheid is die actief wordt misbruikt.

  12. · CISA KEV US

    F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability (CVE-2026-94127)

    CISA added CVE-2026-94127 to the Known Exploited Vulnerabilities catalog. Affected product: F5 BIG-IP APM. Remediation due date: 2026-09-25.