F5 BIG-IP APM OAuth zero-day demands patching and compromise assessment
Confirmed exploitation of a configuration-dependent BIG-IP APM flaw requires organisations to identify OAuth authorisation-server deployments, install engineering hotfixes and investigate pre-patch activity rather than treating version compliance as closure.
Security.io Intelligence Desk · Thursday, 24 September 2026
Executive consequence
F5 reported active exploitation of CVE-2026-94127, a critical BIG-IP APM heap-based buffer overflow affecting virtual servers that combine an APM access policy with an OAuth profile.
Decision today
Inventory BIG-IP APM virtual servers and flag those combining an access policy with an OAuth profile.
Astrana Health filed an Item 1.05 Form 8-K after determining that a social-engineering-driven incident was material because of the potentially sensitive data involved.
Do today
Brief incident, privacy, legal and payer-relations owners on the SEC filing.
The FBI acknowledged an investigation into claims that FBIJobs.gov was compromised and employee PII affected. It said the point of breach remains undetermined between a third-party provider and its own enterprise.
Do today
Identify every recruitment and applicant portal operated by a third party.
GitGuardian's new measurement shows that a documented GitHub design property—private keys remain valid until manually revoked—has left hundreds of publicly exposed App credentials operational.
Do today
Enumerate all GitHub Apps, installations, permissions and private-key fingerprints.
Rusty deploys data loss prevention by locking a stack of spreadsheets to the desk with heavy chains, guaranteeing nobody can remove them without tools.