CVE-2026-94127 is a critical heap-based buffer overflow (CWE-122) in F5 BIG-IP's Access Policy Manager (APM) module triggered when both an APM access policy and an OAuth profile are configured on a virtual server. An unauthenticated remote attacker can send specially crafted network traffic to achieve arbitrary code execution on the appliance with no authentication or user interaction required. Active exploitation in the wild has been confirmed, making this an immediate critical priority for any organisation running BIG-IP APM with OAuth.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-22
Added to CISA KEV: 2026-09-22 0 DAY BETWEEN CVE AND KEV
CVE-2026-94127 is a critical remote code execution (RCE) vulnerability affecting F5 BIG-IP systems that have both an Access Policy Manager (APM) access policy and an OAuth profile configured on a virtual server. By sending specially crafted malicious traffic to an affected virtual server, an unauthenticated attacker can achieve code execution, posing a severe security risk to organizations relying on BIG-IP for traffic management and security.
Security Advisory Description When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious ... Security Advisory Description When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to…
F5 BIG-IP APM virtual servers with OAuth profiles face CVE-2026-94127, a CVSS 9.8 network unauthenticated RCE. Inventory exposed data-plane VIPs and patch now.
CVE-2026-94127 is a CVSS 9.8 Heap Buffer Overflow vulnerability in F5 BIG IP. See exploitation status, patch guidance, and technical details.
Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-94127, presente in BIG-IP APM. Tale vulnerabilità, qualora sfruttata ...