🔴 CVE-2026-94127

CVE-2026-94127 is a critical heap-based buffer overflow (CWE-122) in F5 BIG-IP's Access Policy Manager (APM) module triggered when both an APM access policy and an OAuth profile are configured on a virtual server. An unauthenticated remote attacker can send specially crafted network traffic to achieve arbitrary code execution on the appliance with no authentication or user interaction required. Active exploitation in the wild has been confirmed, making this an immediate critical priority for any organisation running BIG-IP APM with OAuth.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-22

Added to CISA KEV: 2026-09-22 0 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-09-22)

Summary

CVE-2026-94127 is a critical remote code execution (RCE) vulnerability affecting F5 BIG-IP systems that have both an Access Policy Manager (APM) access policy and an OAuth profile configured on a virtual server. By sending specially crafted malicious traffic to an affected virtual server, an unauthenticated attacker can achieve code execution, posing a severe security risk to organizations relying on BIG-IP for traffic management and security.

Exploitation

  • Active Exploitation: The vulnerability is confirmed to be actively exploited in the wild [1][4].
  • Threat Actors/Campaigns: Specific threat actor groups or ransomware campaigns have not been definitively named in public advisories as of the current date, though active in-the-wild exploitation is documented [1].
  • PoC/Exploit Tool Availability: Public reporting indicates the vulnerability is a CVSS 9.8 issue [2][3], and exploitation technical details have been discussed, though users should consult F5's official guidance for specific mitigation.
  • Attack Prerequisites: This is a network-based attack that does not require authentication or user interaction [1].

Affected Products & Patches

  • Affected Product Versions: F5 BIG-IP systems (including those in Appliance mode) utilizing both an APM access policy and an OAuth profile on a virtual server are affected [1].
  • Patch/Hotfix: Users should immediately refer to the official F5 security advisory (K000162605) for the latest available patches or hotfixes applicable to their specific BIG-IP software versions [1].
  • Mitigations: Organizations are advised to audit their configurations to identify exposed data-plane virtual servers (VIPs) using the vulnerable combination of features and apply recommended software updates immediately [2].

Impact

  • Access/Capability: Successful exploitation grants an unauthenticated attacker the ability to execute arbitrary code on the affected BIG-IP system, potentially leading to a full system compromise [1].
  • Business Risk: For internet-facing deployments, this vulnerability presents an extreme risk, as it allows external attackers to bypass authentication entirely to gain control over critical infrastructure, which can result in unauthorized access to backend networks, data exfiltration, or complete service disruption.

Sources

  1. K000162605: BIG-IP APM vulnerability CVE-2026-94127

    Security Advisory Description When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious ... Security Advisory Description When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to…

  2. CVE-2026-94127: F5 BIG-IP APM OAuth Unauthenticated RCE — Detection and ...

    F5 BIG-IP APM virtual servers with OAuth profiles face CVE-2026-94127, a CVSS 9.8 network unauthenticated RCE. Inventory exposed data-plane VIPs and patch now.

  3. CVE-2026-94127: F5 BIG IP Heap Buffer Overflow | CVETodo

    CVE-2026-94127 is a CVSS 9.8 Heap Buffer Overflow vulnerability in F5 BIG IP. See exploitation status, patch guidance, and technical details.

  4. F5 BIG-IP: rilevato sfruttamento in rete della CVE-2026- ...

    Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-94127, presente in BIG-IP APM. Tale vulnerabilità, qualora sfruttata ...