chiprook
← Security
SecuritySeptember 23, 2026, 07:00

F5 patches exploited CVSS 9.8 flaw in BIG-IP APM

F5 disclosed CVE-2026-94127, a heap-based buffer overflow in BIG-IP Access Policy Manager rated 9.8 that lets an unauthenticated remote attacker execute code on the appliance. The flaw is already being exploited; affected branches are 21.1.0, 17.5.0–17.5.1 and 17.1.0–17.1.3, with hotfixes and an emergency iRule available.

F5 patches exploited CVSS 9.8 flaw in BIG-IP APM
#F5#BIG-IP
Read next
Security

WatchGuard: AI tooling shifts attacks to precision strikes

Security

Scammers Use AI Images to Swap Business Phone Numbers on Google Maps

Security

14,913 Kubernetes Dashboards Found Exposed on the Public Internet

Security

44,897 Printers Expose Raw Print Port 9100 on the Open Internet