SPOJENO AI KEV ✓ EPSS 0.01
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. [...]
F5 RO SE US HU FR CA EU IT NL
CVE v události 1
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-94127 | 9.8 3.1 · f5 9.3 4.0 · f5 | KEV ✓ | 0.01 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.
Jak se o tom psalo 12
-
· DNSC Rumunsko RO
ALERTĂ: Vulnerabilitate critică exploatată activ în F5 BIG-IP APM
DESCRIERE CVE-2026-94127 este o vulnerabilitate critică identificată în componenta APM OAut...
-
· CERT-SE SE
Information om kritisk sårbarhet i F5 BIG-IP APM
F5 har publicerat information om en kritisk sårbarhet, CVE-2026-94127, i BIG-IP APM. Sårbarheten kan resultera i att en oautentiserad angripare kan fjärrexekvera godtycklig kod.
-
· Rapid7 US
CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM
OverviewOn September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.BIG-IP APM provides identity-aware access control for applications and other corporate resources…
-
· NKI Maďarsko HU
Riasztás az F5 BIG-IP APM rendszert érintő CVE-2026-94127 sérülékenységről
A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a BIG-IP Access Policy Manager-t (APM) érintő CVE-2026-94127 azonosítón nyomon követett, kritikus, nulladik napi sérülékenység kapcsán. A sérülékenység egy heap-alapú puffertúlcsordulás, amely hitelesítés nélküli távoli kódfuttatást tehet lehetővé az érintett BIG-IP rendszereken. A sebezhetőség a CVSS v3.1 pontozási rendszer alapján 9,8-as súlyossági besorolást kapott. Ha egy […]
-
· BleepingComputer US nadpis události
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. [...]
-
· CERT-FR – avis FR
Vulnérabilité dans F5 BIG-IP (23 septembre 2026)
Une vulnérabilité a été découverte dans F5 BIG-IP. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. L'éditeur indique que la vulnérabilité CVE-2026-94127 est activement exploitée. Des indicateurs de compromission sont disponibles dans l'avis de l'éditeur.
-
· Cyber Centre Kanada CA
AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127
Number: AL26-022Date: September 22, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian…
-
· CERT-EU EU
2026-013: Critical Vulnerability in F5 BIG-IP APM
On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking appropriate actions as soon as possible.
-
· Cyber Centre Kanada CA
F5 security advisory (AV26-949)
Serial number: AV26-949Date: September 22, 2026 As of September 22, 2026, F5 is affected by a vulnerability in the following product: BIG-IP Versions 21.1.0 to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG Versions 17.5.0 to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG Versions 17.1.0 to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG F5 has reported that CVE-2026-94127 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they…
-
· CSIRT Itálie (ACN) IT
F5 BIG-IP: rilevato sfruttamento in rete della CVE-2026-94127
Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-94127, presente in BIG-IP APM. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a utenti malintenzionati remoti di eseguire codice arbitrario sui sistemi interessati.
-
· NCSC-NL NL
NCSC-2026-0386 [1.00] [H/H] Kwetsbaarheid verholpen in F5 Networks BIG-IP Access Policy Manager
F5 Networks heeft een kwetsbaarheid verholpen in BIG-IP Access Policy Manager (APM). De kwetsbaarheid stelt een ongeauthenticeerde kwaadwillende in staat om malafide code uit te voeren. Hiertoe dient de kwaadwillende malafide netwerkverkeer naar het kwetsbare systeem te versturen. BIG-IP APM-systemen zijn alleen kwetsbaar wanneer een access policy en een OAuth-profiel op de virtuele server zijn geconfigureerd. F5 Networks geeft aan dat het een zeroday-kwetsbaarheid is die actief wordt misbruikt.
-
· CISA KEV US
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability (CVE-2026-94127)
CISA added CVE-2026-94127 to the Known Exploited Vulnerabilities catalog. Affected product: F5 BIG-IP APM. Remediation due date: 2026-09-25.