Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-94127: F5 BIG‑IP APM may allow remote code execution
CVE-2026-94127 · published 18 days ago · actively exploited
Summary
The BIG‑IP Access Policy Manager component can be tricked into running unwanted code when an access policy and an OAuth profile are set on a virtual server. An attacker who can reach the server could take control of it without needing any credentials. Install the latest security updates from F5 and review configuration settings to ensure they are protected.
What to do
- Update f5 big-ip to version Hotfix-BIGIP-21.1.0.2.0.30.22-ENG or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| f5 | big-ip | < Hotfix-BIGIP-21.1.0.2.0.30.22-ENG |
| f5 | big-ip apm | All versions |
| f5 | big-ip_access_policy_manager |
>= 17.0.0, <= 17.1.3 >= 17.5.0, <= 17.5.1 21.1.0 cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* |
Original advisory text
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
References
- https://my.f5.com/manage/s/article/K000162605 Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-... US Government Resource
Internet-facing
3 days
and check for signs of compromise
Internal
3 days
and check for signs of compromise
- Known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
2%
chance of attack within 30 days
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published22 Sep 2026
Updated9 Oct 2026
First seen22 Sep 2026
Track software like this
Free during beta