CVE-2026-94127
Published Sep 22, 2026
Last updated an hour ago
AI description
CVE-2026-94127 is a heap-based buffer overflow vulnerability found in F5 BIG-IP Access Policy Manager (APM). This flaw specifically affects systems where an access policy and an OAuth profile are configured on a virtual server. The vulnerability allows an unauthenticated attacker to achieve remote code execution by sending specially crafted malicious traffic to the affected BIG-IP APM system. This issue has been observed to be actively exploited in the wild.
- Description
- When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- Source
- f5sirt@f5.com
- NVD status
- Analyzed
- Products
- big-ip_access_policy_manager
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Exploit added on
- Sep 22, 2026
- Exploit action due
- Sep 25, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- f5sirt@f5.com
- CWE-122
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
11
🐦 🚨 Active exploitation alert: F5 BIG-IP APM RCE (CVE-2026-94127, CVSS 9.8) and Check Point mgmt-server path traversal (CVE-2026-93616) exploited in the wild — patch now. Also on CISA KEV: Arista VeloCloud Orchestrator (CVSS 10.0). #infosec #CVE #0day
@ita_ipo
23 Sept 2026
61 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM — Detection, Expo… "On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a heap-based…" 🔗 https://t.co/5sJbaAu33f #CyberSecurity #ThreatIntel #critical #zeroday #
@SecurityAr58409
23 Sept 2026
27 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-94127: F5 BIG-IP APM OAuth Unauthenticated RCE — Detection, Triage, an… "On September 22, 2026, F5 disclosed CVE-2026-94127 — a critical vulnerability in BIG-IP Access…" 🔗 https://t.co/oyiMQiBhJS #CyberSecurity #ThreatIntel #critical #z
@SecurityAr58409
23 Sept 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
F5 Patches Actively Exploited BIG-IP APM Zero-Day (CVE-2026-94127) F5 has released patches for CVE-2026-94127, an actively exploited zero-day RCE vulnerability in BIG-IP APM devices configured as… Full write-up → link in bio #cybersecurity #infosec #VulnerabilityDisclosure
@HotaSamit
23 Sept 2026
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
F5 BIG-IP APM, Check Point Security Gateway und VeloCloud Orchestrator stehen wegen aktiv ausgenutzter Sicherheitslücken im Fokus. Ein Überblick über CVE-2026-94127, CVE-2026-85102, CVE-2026-93616 und CVE-2026-93952. https://t.co/UIVtmEjfy1
@oliverjessner
23 Sept 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。Check Point複数製品のCVE-2026-85102+CVE-2026-93616、Arista VeloCloud OrchestratorのCVE-2026-93952、F5 BIG-IP APMのCVE-20
@__kokumoto
23 Sept 2026
679 Impressions
0 Retweets
1 Like
1 Bookmark
1 Reply
0 Quotes
F5 BIG-IP APM Critical Heap Overflow (CVE-2026-94127) Allows Unauthenticated RCE A critical heap-based buffer overflow in F5 BIG-IP APM (CVE-2026-94127) allows unauthenticated remote attackers to execute code via… Full write-up → link in bio #cybersecurity #infosec #cve #ke
@HotaSamit
23 Sept 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CISA ADDS FOUR KNOWN EXPLOITED VULNERABILITIES — F5 BIG-IP APM CVE-2026-94127 LEADS CISA has updated the Known Exploited Vulnerabilities catalog (2026.09.22, 1721 entries) with four additions. The new lead for operators is F5 BIG-IP APM CVE-2026-94127, which was not
@DailyDarkWeb
22 Sept 2026
5609 Impressions
1 Retweet
11 Likes
4 Bookmarks
0 Replies
1 Quote
New vulnerability disclosed: CVE-2026-94127. F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability. Worth reviewing if this affects your stack. Details: https://t.co/c5dLy169H2 #CVE #InfoSec #VulnMgmt
@Prateektomar
22 Sept 2026
64 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-94127: F5 BIG-IP APM OAuth Unauthenticated RCE — Detection and Remedia… "NVD has published CVE-2026-94127 as a CVSS 9.8 Critical, network-exploitable…" 🔗 https://t.co/gV1LDqepEk #CyberSecurity #ThreatIntel #cve202694127 #critical #cve
@SecurityAr58409
22 Sept 2026
67 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E2AC01C3-F47E-4F42-A4EB-90DE63C834CC",
"versionEndIncluding": "17.1.3",
"versionStartIncluding": "17.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BD71EC53-8ABC-410F-B031-0B3288D2E8DF",
"versionEndIncluding": "17.5.1",
"versionStartIncluding": "17.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:21.1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "8D26D424-54C1-4B2C-BBB8-C79E925BED7F",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]