CVE-2026-94127

Published Sep 22, 2026

Last updated an hour ago

Exploit knownCVSS critical 9.3
Network
Zero-day
IoT
Supply chain
VPN
BIG-IP APM
BIG-IP
OAuth Authorization Server

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-94127 is a heap-based buffer overflow vulnerability found in F5 BIG-IP Access Policy Manager (APM). This flaw specifically affects systems where an access policy and an OAuth profile are configured on a virtual server. The vulnerability allows an unauthenticated attacker to achieve remote code execution by sending specially crafted malicious traffic to the affected BIG-IP APM system. This issue has been observed to be actively exploited in the wild.

Description
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source
f5sirt@f5.com
NVD status
Analyzed
Products
big-ip_access_policy_manager

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
Exploit added on
Sep 22, 2026
Exploit action due
Sep 25, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

f5sirt@f5.com
CWE-122

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

11

  1. 🐦 🚨 Active exploitation alert: F5 BIG-IP APM RCE (CVE-2026-94127, CVSS 9.8) and Check Point mgmt-server path traversal (CVE-2026-93616) exploited in the wild — patch now. Also on CISA KEV: Arista VeloCloud Orchestrator (CVSS 10.0). #infosec #CVE #0day

    @ita_ipo

    23 Sept 2026

    61 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🔒 #CyberSecurity CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM — Detection, Expo… "On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a heap-based…" 🔗 https://t.co/5sJbaAu33f #CyberSecurity #ThreatIntel #critical #zeroday #

    @SecurityAr58409

    23 Sept 2026

    27 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🔒 #CyberSecurity CVE-2026-94127: F5 BIG-IP APM OAuth Unauthenticated RCE — Detection, Triage, an… "On September 22, 2026, F5 disclosed CVE-2026-94127 — a critical vulnerability in BIG-IP Access…" 🔗 https://t.co/oyiMQiBhJS #CyberSecurity #ThreatIntel #critical #z

    @SecurityAr58409

    23 Sept 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. F5 Patches Actively Exploited BIG-IP APM Zero-Day (CVE-2026-94127) F5 has released patches for CVE-2026-94127, an actively exploited zero-day RCE vulnerability in BIG-IP APM devices configured as… Full write-up → link in bio #cybersecurity #infosec #VulnerabilityDisclosure

    @HotaSamit

    23 Sept 2026

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. F5 BIG-IP APM, Check Point Security Gateway und VeloCloud Orchestrator stehen wegen aktiv ausgenutzter Sicherheitslücken im Fokus. Ein Überblick über CVE-2026-94127, CVE-2026-85102, CVE-2026-93616 und CVE-2026-93952. https://t.co/UIVtmEjfy1

    @oliverjessner

    23 Sept 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。Check Point複数製品のCVE-2026-85102+CVE-2026-93616、Arista VeloCloud OrchestratorのCVE-2026-93952、F5 BIG-IP APMのCVE-20

    @__kokumoto

    23 Sept 2026

    679 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  7. F5 BIG-IP APM Critical Heap Overflow (CVE-2026-94127) Allows Unauthenticated RCE A critical heap-based buffer overflow in F5 BIG-IP APM (CVE-2026-94127) allows unauthenticated remote attackers to execute code via… Full write-up → link in bio #cybersecurity #infosec #cve #ke

    @HotaSamit

    23 Sept 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CISA ADDS FOUR KNOWN EXPLOITED VULNERABILITIES — F5 BIG-IP APM CVE-2026-94127 LEADS CISA has updated the Known Exploited Vulnerabilities catalog (2026.09.22, 1721 entries) with four additions. The new lead for operators is F5 BIG-IP APM CVE-2026-94127, which was not

    @DailyDarkWeb

    22 Sept 2026

    5609 Impressions

    1 Retweet

    11 Likes

    4 Bookmarks

    0 Replies

    1 Quote

  9. New vulnerability disclosed: CVE-2026-94127. F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability. Worth reviewing if this affects your stack. Details: https://t.co/c5dLy169H2 #CVE #InfoSec #VulnMgmt

    @Prateektomar

    22 Sept 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🔒 #CyberSecurity CVE-2026-94127: F5 BIG-IP APM OAuth Unauthenticated RCE — Detection and Remedia… "NVD has published CVE-2026-94127 as a CVSS 9.8 Critical, network-exploitable…" 🔗 https://t.co/gV1LDqepEk #CyberSecurity #ThreatIntel #cve202694127 #critical #cve

    @SecurityAr58409

    22 Sept 2026

    67 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations