• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-94127: pre-auth remote code execution in F5 BIG-IP APM

Unauthenticated attackers can achieve remote code execution against F5 BIG-IP APM when an access policy and an OAuth Authorization Server profile are configured on a virtual server. CVE-2026-94127 is a heap-based buffer overflow affecting BIG-IP branches 21.1.0 through before Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, 17.5.0 through before Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, and 17.1.0 through before Hotfix-BIGIP-17.1.3.5.0.41.14-ENG; an attacker only needs network access to the vulnerable virtual server and does not require valid credentials when APM is acting as an OAuth Authorization Server.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.02226
CWE
CWE-122
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: CISA added this issue to its Known Exploited Vulnerabilities list with a fast remediation deadline, and public exploit code exists — prioritize patching or mitigation for internet-facing BIG-IP APM instances configured as OAuth Authorization Servers.

What is CVE-2026-94127?

Unauthenticated attackers can achieve remote code execution against F5 BIG-IP APM when an access policy and an OAuth Authorization Server profile are configured on a virtual server. CVE-2026-94127 is a heap-based buffer overflow affecting BIG-IP branches 21.1.0 through before Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, 17.5.0 through before Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, and 17.1.0 through before Hotfix-BIGIP-17.1.3.5.0.41.14-ENG; an attacker only needs network access to the vulnerable virtual server and does not require valid credentials when APM is acting as an OAuth Authorization Server. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of F5 BIG-IP APM are affected?

BRANCHAFFECTEDFIXED
BIG-IP21.1.0 – before Hotfix-BIGIP-21.1.0.2.0.30.22-ENGHotfix-BIGIP-21.1.0.2.0.30.22-ENG
BIG-IP17.5.0 – before Hotfix-BIGIP-17.5.1.9.0.160.12-ENGHotfix-BIGIP-17.5.1.9.0.160.12-ENG
BIG-IP17.1.0 – before Hotfix-BIGIP-17.1.3.5.0.41.14-ENGHotfix-BIGIP-17.1.3.5.0.41.14-ENG

Is CVE-2026-94127 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-22, and US federal agencies were required to remediate by 2026-09-25. Public exploit code is available.

How to fix CVE-2026-94127

  1. Apply the vendor hotfix for your branch: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, or Hotfix-BIGIP-17.1.3.5.0.41.14-ENG as appropriate.
  2. If you cannot patch immediately, restrict network exposure to vulnerable virtual servers and block untrusted access to APM OAuth Authorization Server endpoints.
  3. Follow F5’s guidance for any additional mitigations and monitoring recommendations, and watch for signs of compromise in affected systems.
  4. Monitor logs and endpoints for indicators of exploitation and apply incident response procedures if suspicious activity is found.

Frequently asked questions

Is CVE-2026-94127 being actively exploited?

CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog on 2026-09-22 with a remediation due date of 2026-09-25, and public exploit code is publicly available.

Which BIG-IP APM versions are affected by CVE-2026-94127?

BIG-IP APM is affected in 21.1.0 up to before Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, 17.5.0 up to before Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, and 17.1.0 up to before Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.

Is there a patch for CVE-2026-94127?

Yes. F5 published hotfixes: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG for the affected branches.

Does CVE-2026-94127 require authentication?

No authentication is required to exploit this vulnerability, but it only applies when BIG-IP APM is configured as an OAuth Authorization Server on the virtual server.

References