AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127

Imported from official source

Cybersecurity Classified by Officially

Number: AL26-022
Date: September 22, 2026

This Alert is intended for IT professionals and managers.

An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

The Canadian Centre for Cyber Security (Cyber Centre) is aware of a critical vulnerability affecting F5 BIG IP Access Policy Manager (APM)Footnote 1.

In response to the vendor advisory released on September 22, 2026, the Cyber Centre released AV26-949 on September 22, 2026Footnote 2.

Tracked as CVE-2026-94127Footnote 3, this vulnerability is a Heap-based Buffer Overflow (CWE-122)Footnote 4 and it affects F5 BIG-IP systems where an APM access policy and an OAuth profile are configured on the same virtual server. Under these conditions, specially crafted malicious traffic may allow an unauthenticated attacker to execute arbitrary code on the affected device, potentially resulting in remote code execution and full system compromise.

F5 has indicated that CVE-2026-94127 is being exploited in the wild.

The Cyber Centre strongly recommends that organizations running affected F5 BIG‑IP APM deployments upgrade to the following vendor-supported fixed hotfix releases:

The Cyber Centre also recommends organizations to:

  • Identify vulnerable BIG IP systems that have both an APM access policy and an OAuth profile configured on a virtual server.
  • Apply the vendor-provided iRule (contact F5 Support to obtain the iRule)Footnote 1.
  • Review access logs for indicators of compromise (IoC), particularly OAuth authentication failures especially in rapid succession or large volumeFootnote 1. Also review administrative accounts, access policies for any signs of suspicious activity.
  • Upgrade to a vendor-supported fixed software version as soon as possible.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://cyber.gc.ca/en/alerts-advisories/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127

    Officially imported this from Canadian Centre for Cyber Security’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    This publication has changed since it was first published

    2 versions recorded. The original is kept in full — nothing is overwritten.

    1. v2 imported change on current
    2. v1 as first published on

    Provenance

    Organization
    Canadian Centre for Cyber Security — imported from official source
    Official source
    https://www.cyber.gc.ca/api/cccs/rss/v1/get?feed=alerts_advisories&lang=en ATOM
    Imported
    September 22, 2026 20:00
    Versions
    2 recorded
    Identity
    https://cyber.gc.ca/en/alerts-advisories/al26-022-vulnerability-impacting-f5-big-ip-acc...

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.