SECURITY·중요도 9·2026. 09. 23.·The Hacker News
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
── KO ──────────────────
F5 BIG-IP APM의 취약점이 악용되어 인증 없이 코드 실행이 가능해졌다고 보고됨.
F5는 BIG-IP Access Policy Manager(APM)에서 발생한 치명적인 취약점에 대해 경고했습니다. 이 취약점(CVE-2026-94127)은 공격자가 로그인 없이도 시스템에서 코드를 실행할 수 있게 합니다. 이 취약점은 APM이 OAuth 권한 서버로 작동하는 시스템에만 영향을 미치며, F5에서는 9월 22일에 이를 공개하고 핫픽스를 배포했습니다.
── EN ──────────────────
A critical flaw in F5 BIG-IP APM allows unauthenticated RCE, impacting OAuth servers.
F5 has issued a warning regarding a critical flaw in its BIG-IP Access Policy Manager (APM). This vulnerability, identified as CVE-2026-94127, enables attackers to execute code on the system without logging in. It affects systems where APM acts as an OAuth authorization server. F5 disclosed the issue on September 22 and has released hotfixes for it.