---
title: F5修复BIG-IP APM零日漏洞以应对远程代码执行攻击
url: https://www.dataloco.com/zh/f5big-ip-apm-2
published: 2026-09-26T02:23:46+00:00
language: zh
section: 安全
source: https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/
organizations: F5, Shadowserver, CISA
publisher: Dataloco
---

# F5修复BIG-IP APM零日漏洞以应对远程代码执行攻击

F5发布了安全更新，以解决一个关键的BIG-IP APM零日漏洞，该漏洞正在被远程代码执行攻击利用。

BIG-IP APM（即访问策略管理器）是该公司的集中访问管理代理解决方案，帮助管理员保护对其组织网络、应用程序、云和应用程序编程接口的访问。

该漏洞被跟踪为CVE-2026-94127，影响配置为OAuth授权服务器的实例，当BIG-IP APM访问策略和OAuth配置在虚拟服务器上时。

F5在周二发布的安全通告中警告称：“我们了解到此漏洞已被利用。” “严格作为OAuth客户端/资源服务器使用APM的部署（未配置OAuth授权服务器配置）不受此漏洞影响。”

该公司建议客户检查系统以获取妥协指标，如果检测到多个OAuth身份验证失败和可疑命令的组合，紧接着出现TMM SIGABRT。

F5还分享了针对无法立即安装安全更新的管理员的缓解措施，要求将iRule（可从F5支持处获取）应用于受影响的BIG-IP APM虚拟服务器。

互联网威胁监测非营利组织Shadowserver目前追踪着超过14,700个带有BIG-IP APM指纹的IP地址。然而，目前尚不清楚有多少已被修补或是蜜罐。

## This story in other languages

- [Nederlands](https://www.dataloco.com/nl/f5-patches-kritieke-zero-day-in-big-ip-apm-voor-oauth-servers)
- [Svenska](https://www.dataloco.com/sv/f5-slapper-sakerhetspatch-for-kritisk-big-ip-apm-sarbarhet-utnyttjad-i-fjarrkorningsexplosioner)
- [Français](https://www.dataloco.com/fr/f5-corrige-une-faille-critique-dans-big-ip-apm-exploitee-pour-execution-de-code-non-authentifiee-sur-serveurs-oauth)
- [Norsk](https://www.dataloco.com/no/f5-har-rettet-en-kritisk-sarbarhet-i-big-ip-apm-som-ble-utnyttet-til-fjernkjoring-av-kode)
- [日本語](https://www.dataloco.com/ja/f5big-ip-apm)
- [한국어](https://www.dataloco.com/ko/f5-big-ip-apm)
- [Bahasa Indonesia](https://www.dataloco.com/id/f5-mengeluarkan-pembaruan-keamanan-untuk-celah-nol-hari-big-ip-apm-yang-dieksploitasi-dalam-serangan-kode-eksekusi-jauh)
