CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM
Imported from official source
OverviewOn September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.BIG-IP APM provides identity-aware access control for applications and other corporate resources and can integrate with authentication technologies including OAuth, OpenID Connect, and SAML. CVE-2026-94127 is not exposed in a default configuration: exploitation requires a BIG-IP virtual server with both an APM access policy and an OAuth profile configured. Because affected BIG-IP systems may process traffic at an organization's network edge, organizations using this configuration should prioritize remediation.The vulnerability affects the data plane and does not expose the BIG-IP control plane. BIG-IP systems operating in Appliance mode are also affected.F5 lists the following affected release trains and corresponding fixed hotfixes:BIG-IP 21.1.0: versions prior to Hotfix-BIGIP-21.1.0...
This version
- Version
- 1 of 2
- Recorded
- September 23, 2026 10:00
- Change
- Initial
- Content hash
9ed2b1dbfac2990cf9e7130b84e4cab4- All versions
- Revision history