CiberLATAMbywhalemate

CVE-2026-94127 affects F5 BIG-IP APM

F5 and security agencies warned of an exploited flaw in BIG-IP APM that can enable unauthenticated RCE and is now in CISA’s KEV.

Whalemate Labs · AI-assisted researchPublished:2 min read

F5 issued an advisory on CVE-2026-94127 in BIG-IP APM and confirmed the vulnerability has been exploited. The heap overflow can allow unauthenticated remote code execution when an access policy and an OAuth profile are configured on the same virtual server.

F5 has issued an advisory on CVE-2026-94127 in BIG-IP APM and confirmed that the vulnerability has already been exploited. The heap-based buffer overflow can allow unauthenticated remote code execution when an access policy and an OAuth profile are configured on the same virtual server. CISA added the issue to its Known Exploited Vulnerabilities Database on September 22, 2026.

What did F5 report about the flaw?

F5 described CVE-2026-94127 as a heap overflow vulnerability, tracked as CWE-122, that can enable unauthenticated RCE in BIG-IP APM under a specific configuration. According to the company’s advisory, the issue appears when an access policy and an OAuth profile are configured on the same virtual server.

The company also pointed to hotfixes for the 21.1.0, 17.5.x, and 17.1.x branches as mitigation for affected versions. The official CVE record also says the flaw is only present when BIG-IP APM is configured as an OAuth Authorization Server.

Which systems are out of scope?

The CVE record says deployments that use APM only as an OAuth Client or Resource Server are not affected. SecurityWeek reported the same, noting that F5 considers those deployments non-vulnerable and did not identify other affected products.

CVE.org also says BIG-IP in Appliance mode is vulnerable and that this is a data plane issue, with no exposure of the control plane. NetworkWorld added that affected implementations include systems configured in appliance mode and that exploitation requires APM and an OAuth authorization server profile to coexist.

What did agencies and analysts say?

CERT-EU said CVE-2026-94127 affects F5 BIG-IP APM and allows an unauthenticated attacker to achieve remote code execution on the affected device. The Canadian Centre for Cyber Security said CISA added the vulnerability to its KEV database on September 22, 2026.

The Canadian agency’s updated advisory lists as vulnerable BIG-IP 21.1.0 earlier than the corresponding hotfix, 17.5.0 through 17.5.1 earlier than the hotfix, and 17.1.0 through 17.1.3 earlier than the hotfix. Beazley Security Labs also described the case as an actively exploited vulnerability and published an independent analysis of the incident.

SOC Prime said the attack requires specially crafted traffic aimed at an affected OAuth configuration and characterized the impact as arbitrary code execution by a remote, unauthenticated attacker. The Register, meanwhile, reported that the flaw was being actively exploited on F5 BIG-IP APM systems configured as an OAuth Authorization Server with an access policy and OAuth profile on the same virtual server.

Sources

View all