F5 and Check Point rush out fixes for critical flaws already exploited against access and management servers
F5's BIG-IP APM bug hits OAuth authorization server setups, and Check Point says a Management Server path traversal has been exploited since July 23.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
Two security vendors disclosed critical vulnerabilities that attackers are already exploiting. On Tuesday, F5 released updates for CVE-2026-94127, a remote code execution flaw in BIG-IP Access Policy Manager (APM). It affects instances configured as an OAuth Authorization Server, meaning an APM access policy and an OAuth profile on a virtual server. "We have learned that this vulnerability has been exploited," F5 said. Deployments that use APM only as an OAuth client or resource server are not affected. F5 told customers to look for multiple OAuth authentication failures and suspicious commands, followed shortly by a TMM SIGABRT. Admins who cannot update yet can apply an iRule. Shadowserver tracks more than 14,700 IP addresses with BIG-IP APM fingerprints. Check Point released emergency fixes for CVE-2026-93616, a pre-authentication path traversal in its Management web service. The bug lets attackers upload and run arbitrary scripts. It affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent, and has been exploited as far back as July 23. Check Point said it is aware of "a handful of customers who have been attacked" and published indicators of compromise. The company also said a Quantum Security Gateway RCE flaw it patched on September 9, CVE-2026-85102, is now being probed. Vice president of research Lotem Finkelstein said attempts are targeting Spark customers globally.
Sources
- BleepingComputerF5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
- The Hacker NewsF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
- Help Net SecurityAttackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances - Help Net Security
- Security AffairsCheck Point Fixes a New Actively Exploited Critical Security Flaw