F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

A critical zero-day vulnerability in F5’s BIG-IP Application Delivery Controller (ADC) has been exploited, granting attackers unauthenticated remote code execution on OAuth servers. This security flaw affects a staggering number of organizations worldwide, making it an urgent matter for IT teams to patch their systems immediately.

The vulnerability, designated as CVE-2026-0001, resides in F5’s BIG-IP APM (Access Policy Manager) module, which is used by many companies to manage user access and authentication. Attackers exploiting this flaw can execute arbitrary code on affected servers without needing any credentials or authentication. This means that even if an organization has robust security measures in place, a single vulnerability like this can still be exploited.

The exploitation of CVE-2026-0001 is particularly concerning because it allows attackers to gain unauthorized access to sensitive systems and data. OAuth servers, which are responsible for authenticating users and granting them access to protected resources, become vulnerable to remote code execution attacks. This can lead to a range of malicious activities, including data theft, account takeovers, and even the deployment of malware on compromised networks.

The key to this exploit lies in F5’s BIG-IP APM module’s handling of OAuth requests. The module is designed to manage cross-domain privilege escalation, which enables users to access resources across different domains without needing explicit permissions. However, it appears that a flaw in this logic has been exploited by attackers, allowing them to execute arbitrary code on affected servers.

The widespread impact of CVE-2026-0001 cannot be overstated. F5 estimates that over 10,000 organizations worldwide use its BIG-IP APM module, making this vulnerability one of the most significant security concerns in recent history. As a result, IT teams must prioritize patching their systems as soon as possible to mitigate the risk of exploitation.

In light of this urgent situation, it’s essential for organizations to take immediate action. F5 has released patches for the affected BIG-IP APM module, and users are advised to apply these updates without delay. Furthermore, IT teams should review their security protocols and ensure that they have robust monitoring in place to detect any suspicious activity that may indicate exploitation of this vulnerability.


Source: The Hacker News — 2026-09-23