Skip to finding
important · Edge — BIG-IP

An unauthenticated request can execute code on an actively exploited BIG-IP APM virtual server.

Affects

F5 BIG-IP Access Policy Manager, an enterprise access and authentication gateway appliance.

Exposure is limited to virtual servers combining an APM access policy with an OAuth profile; there, crafted unauthenticated traffic triggers a heap overflow and arbitrary code execution.

Detail and 5 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 23, 2026