F5 Networks has issued emergency hotfixes to patch a critical zero-day vulnerability in its BIG-IP Access Policy Manager (APM), which is being actively exploited for unauthenticated remote code execution (RCE). The flaw, designated CVE-2026-94127, impacts a high-risk configuration, making urgent remediation essential.

According to a September 22 advisory from F5, the vulnerability specifically affects systems where BIG-IP APM is configured as an OAuth 2.0 authorization server. In this role, the appliance manages user authentication and issues access tokens for downstream applications. A compromise at this central trust point could jeopardize the authentication framework for numerous interconnected services.

The company confirmed that attackers are using the flaw to execute arbitrary code without credentials. In response, F5 has released engineering hotfixes and strongly advises all affected organizations to deploy them immediately.

For administrators in Hong Kong, the first step is to audit their BIG-IP APM configurations to identify any instances functioning as OAuth authorization servers, typically those handling token issuance for single sign-on (SSO) systems. Upon identifying affected systems, the primary action is to apply the relevant hotfix without delay, given the confirmed active exploitation. Additionally, security teams should scrutinize appliance logs for indicators of compromise, such as unexpected processes or suspicious outbound network connections.

This incident highlights the severe risk facing core identity and access management infrastructure. Protecting central authentication services like OAuth servers is paramount, as their failure can cascade across an organization's entire digital estate. The discovery and disclosure of this zero-day underscore the persistent and critical threats targeting foundational network technologies. Organizations must treat this patch as a top-tier priority and ensure their monitoring and response plans are prepared for breaches of essential authentication services.


F5 Networks 已發佈緊急熱修補程式,用於修補其 BIG-IP 存取策略管理器(APM)中的一個嚴重零日漏洞,該漏洞正被積極利用以進行未經身份驗證的遠端代碼執行(RCE)。被指定為 CVE-2026-94127 的此漏洞影響一個高風險配置,使得緊急修復至關重要。

根據 F5 在 9 月 22 日發佈的公告,該漏洞特別影響那些將 BIG-IP APM 設定為 OAuth 2.0 授權伺服器的系統。在此角色中,該裝置管理使用者驗證並為下游應用程式發放存取權杖。在此中央信任點上的入侵,可能危及眾多互連服務的驗證框架。

該公司證實,攻擊者正在利用此漏洞無需憑證即可執行任意程式碼。作為回應,F5 已發佈工程熱修補程式,並強烈建議所有受影響的組織立即部署它們。

對於香港的管理員而言,第一步是審計其 BIG-IP APM 配置,識別任何作為 OAuth 授權伺服器運作的實例,通常是那些處理單一登入(SSO)系統權杖發放的系統。識別出受影響系統後,鑒於已確認存在積極利用情況,主要行動是立即應用相關熱修補程式。此外,安全團隊應仔細檢查裝置日誌以尋找入侵指標,例如意外的程序或可疑的出站網絡連接。

此事件突顯了核心身份與存取管理基礎設施面臨的嚴重風險。保護如 OAuth 伺服器等中央驗證服務至關重要,因為它們的故障可能在其整個數位資產中引發連鎖反應。此零日漏洞的發現與披露,突顯了針對基礎網絡技術的持續且關鍵的威脅。組織必須將此修補視為最高優先級事項,並確保其監控與應對計畫已為關鍵驗證服務的入侵做好準備。