F5 BIG-IP APM Zero-Day
F5 warned on Tuesday that the vulnerability, tracked as CVE-2026-94127, affects BIG-IP Access Policy Manager (APM) instances configured as an OAuth Authorization Server when an access policy and OAuth profile are set on a virtual server. According to F5, deployments using APM strictly as an OAuth Client or Resource Server are not affected.
"We have learned that this vulnerability has been exploited," F5 said in a security advisory. The company advised customers to review systems for indicators of compromise, such as multiple OAuth authentication failures followed by suspicious commands and a TMM SIGABRT.
Internet threat monitoring non-profit Shadowserver currently tracks over 14,700 IP addresses with BIG-IP APM fingerprints exposed online, though it is unclear how many are patched or are honeypots.
CISA added the flaw to its Known Exploited Vulnerabilities (KEV) Catalog and ordered U.S. federal agencies to secure their networks against it by Friday. For administrators who cannot immediately install updates, F5 has provided a mitigation iRule.
Check Point Security Management Server Zero-Day
Check Point released emergency hotfixes on Monday for a critical path traversal vulnerability (CVE-2026-93616) in its Security Management Server. The flaw allows unauthenticated attackers to upload and execute arbitrary scripts in low-complexity attacks.
Tracked as CVE-2026-93616, the vulnerability affects the Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Check Point addressed it in the R82.20 Security Hotfix.
"This vulnerability is exploited in the wild. Check Point is aware of a handful of customers who have been attacked," the company warned. It provided temporary mitigation measures including placing vulnerable systems behind a firewall and limiting access via Trusted Clients in SmartConsole.
Check Point also shared indicators of compromise in its security advisory. CISA and the FBI have urged software vendors since May 2024 to eliminate path traversal weaknesses from products before shipping, calling such issues "unforgivable."
Both vendors have been targeted by attackers in recent years. Two years ago, CISA flagged a Check Point Quantum Security Gateway flaw as actively exploited by ransomware gangs. F5 vulnerabilities have also been exploited by cybercrime and state-backed groups to breach corporate networks.