HIGHVulnerability
Verified
Global
CISA KEV: F5 BIG-IP APM — F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
Analysis
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-22. Remediation due: 2026-09-25.