Select a theme from the list.
Insights

From our experts

Latest
Exploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorColorado Water Attacks Show How Small Utilities Become Physical TargetsJade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersStolen Ribon App Credentials Open BigCommerce Stores to Data TheftNightmareStresser Takedown Strikes at the DDoS-for-Hire EconomyAI-Assisted Exploit Chain Reached OpenAI Staff Accounts and Internal CodeRuntime npm Malware Slips Past Install-Time Supply Chain DefensesExploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorColorado Water Attacks Show How Small Utilities Become Physical TargetsJade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersStolen Ribon App Credentials Open BigCommerce Stores to Data TheftNightmareStresser Takedown Strikes at the DDoS-for-Hire EconomyAI-Assisted Exploit Chain Reached OpenAI Staff Accounts and Internal CodeRuntime npm Malware Slips Past Install-Time Supply Chain Defenses
Security Insight

Exploited F5 OAuth Flaw Opens a Direct Route Into Access Infrastructure

Exploited F5 OAuth Flaw Opens a Direct Route Into Access Infrastructure
Photo by Negative Space on Pexels

F5 has issued engineering hotfixes for an actively exploited BIG-IP Access Policy Manager vulnerability that can provide unauthenticated remote code execution. The critical heap-buffer overflow specifically affects systems configured to operate as OAuth authorization servers, and restricting the management interface does not remove the exposure.

Organizations using certain F5 BIG-IP Access Policy Manager configurations face an urgent patching and investigation task after the disclosure of an actively exploited remote-code-execution vulnerability. The flaw, tracked as CVE-2026-94127, carries a CVSS v3.1 score of 9.8.

A Narrow Configuration With Serious Consequences

The vulnerability affects BIG-IP APM installations acting as OAuth authorization servers. The dangerous configuration combines an APM access policy with an OAuth authorization-server profile on the same virtual server. Specially constructed network traffic sent to that service can trigger a heap-based buffer overflow and allow code execution without authentication.

Systems operating only as OAuth clients or resource servers are not affected, according to the updated scope published by F5. However, organizations should verify the actual configuration rather than assuming that OAuth functionality is unused or limited to a safer role.

A particularly important detail is that the malicious traffic reaches the application-facing virtual server. Restricting access to the BIG-IP management interface therefore does not prevent exploitation. Appliance-mode deployments can also be vulnerable.

Hotfixes and Forensic Review

F5 has released engineering hotfixes for supported branches and offers an iRule mitigation to customers who cannot install the correction immediately. End-of-support versions were not evaluated, leaving their security status uncertain.

Administrators should preserve relevant evidence before making changes, then install the appropriate hotfix and inspect the appliance for suspicious activity. Potential warning signs include repeated failed OAuth UserInfo requests, unexplained increases in failed OAuth counters, unusual commands in audit logs and TMM process crashes occurring near suspicious authentication activity.

Recommended Response

  • Identify every APM virtual server using an OAuth authorization-server profile.
  • Apply the branch-specific engineering hotfix or obtain the temporary iRule.
  • Retain APM, audit and system logs before remediation.
  • Investigate suspicious commands and authentication failures.
  • Rotate exposed credentials if compromise cannot be excluded.

In my view, patching alone is not sufficient when exploitation has already been confirmed. An attacker who obtained execution may have established another access path that survives the update. Affected appliances should be treated as potentially compromised security infrastructure and subjected to a disciplined incident-response process.

Talk to our team →

Latest

Exploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureSep 24, 2026AI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsSep 24, 2026Microsoft Builds an Agentic Command Center for the Modern SOCSep 24, 2026OT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITSep 23, 2026Bifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionSep 23, 2026TrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorSep 23, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning4IDScan Lawsuits Put Mass Identity Collection Under the Microscope5Windows LegacyHive Flaw Leaves Administrators Weighing Unofficial Protection6Microsoft Prepares Windows Customers for a Faster Era of AI-Driven Patching