Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

Rapid7 Version 1 original

Imported from official source

OverviewOn September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.BIG-IP APM provides identity-aware access control for applications and other corporate resources and can integrate with authentication technologies including OAuth, OpenID Connect, and SAML. CVE-2026-94127 is not exposed in a default configuration: exploitation requires a BIG-IP virtual server with both an APM access policy and an OAuth profile configured. Because affected BIG-IP systems may process traffic at an organization's network edge, organizations using this configuration should prioritize remediation.The vulnerability affects the data plane and does not expose the BIG-IP control plane. BIG-IP systems operating in Appliance mode are also affected.F5 lists the following affected release trains and corresponding fixed hotfixes:BIG-IP 21.1.0: versions prior to Hotfix-BIGIP-21.1.0...

This version

Version
1 of 2
Recorded
September 23, 2026 10:00
Change
Initial
Content hash
9ed2b1dbfac2990cf9e7130b84e4cab4
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.