2026-09-22 15:03 UTC
EITW 0day in F5 APM.
https://my.f5.com/manage/s/article/K000162605
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). (CVE-2026-94127)
This vulnerability allows an unauthenticated attacker to perform RCE. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.
Replies (1)
-
@fuzzyfuzzyfungus@cyberplace.social 2026-09-22 15:17
@cR0w@infosec.exchange Is there some moderately esoteric architectural arrangement that allows that remotely executed code to run on something that isn't management-related; or is "there is no control plane exposure" grotesque sophistry?