---
title: F5的「BIG-IP APM」发现严重脆弱性
url: https://www.dataloco.com/zh/f5big-ip-apm
published: 2026-09-26T01:21:41+00:00
language: zh
section: 安全
source: https://www.security-next.com/190576
organizations: f5, big-ip, apm
publisher: Dataloco
---

# F5的「BIG-IP APM」发现严重脆弱性

F5提供的「BIG-IP Access Policy Manager（APM）」中确认存在严重脆弱性。该脆弱性已被恶意利用，F5呼吁用户修复漏洞并检查被侵害的情况。

该公司于当地时间9月22日发布了安全顾问，揭示了堆基缓冲区溢出漏洞「CVE-2026-94127」。

在「BIG-IP APM」中，如果虚拟服务器配置了「访问策略」和「OAuth配置文件」，并作为「OAuth授权服务器」进行设置，则可能由于恶意流量导致任意代码的执行。

该漏洞还影响了设备模式，其在通用漏洞评分系统「CVSSv4.0」中的基本评分为「9.3」，在「CVSSv3.1」中为「9.8」，属于四个等级中最高的「严重（Critical）」级别。

F5内部发现了该漏洞，且已确认该漏洞已被恶意利用。

## This story in other languages

- [Deutsch](https://www.dataloco.com/de/schwere-sicherheitsanfalligkeit-bei-big-ip-apm-entdeckt)
- [Français](https://www.dataloco.com/fr/vulnerabilite-critique-dans-big-ip-apm-confirmee)
- [Türkçe](https://www.dataloco.com/tr/f5-big-ip-apm-urununde-kritik-guvenlik-acigi-tespit-edildi)
- [Русский](https://www.dataloco.com/ru/obnaruzena-uiazvimost-v-big-ip-apm-uze-zafiksirovano-zloupotreblenie)
- [हिन्दी](https://www.dataloco.com/hi/f5-ka-big-ip-apm-ma-gabhara-sarakashha-samasaya-pahal-sa-ha-tharapayaga-ha-caka-ha)
- [Polski](https://www.dataloco.com/pl/wykryto-powazna-luke-w-systemie-big-ip-apm)
- [العربية](https://www.dataloco.com/ar/thghr-amny-khtyr-fy-big-ip-apm)
- [English](https://www.dataloco.com/en/f5-reveals-critical-heap-buffer-overflow-in-big-ip-apm)
- [Português (Brasil)](https://www.dataloco.com/pt-br/vulnerabilidade-critica-encontrada-no-big-ip-apm-da-f5)
- [ไทย](https://www.dataloco.com/th/big-ip-apm)
