AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127

Canadian Centre for Cyber Security Version 2 imported change current

Imported from official source

Number: AL26-022Date: September 22, 2026 This Alert is intended for IT professionals and managers. An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. The Canadian Centre for Cyber Security (Cyber Centre) is aware of a critical vulnerability affecting F5 BIG IP Access Policy Manager (APM)Footnote 1. In response to the vendor advisory released on September 22, 2026, the Cyber Centre released AV26-949 on September 22, 2026Footnote 2. Tracked as CVE-2026-94127Footnote 3, this vulnerability is a Heap-based Buffer Overflow (CWE-122)Footnote 4 and it affects F5 BIG-IP systems where an APM access policy and an OAuth profile are configured on the same virtual server. Under these conditions, specially crafted malicious traffic may allow an unauthenticated attacker to execute arbitrary code on the affected device, potentially resulting in remote code execution and full sy...

This version

Version
2 of 2
Recorded
September 24, 2026 17:00
Change
Imported change
Content hash
23fc65f2a1b02ed92c0de71f14180baf
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.