F5 BIG-IP Remote Code Execution Vulnerability

Imported from official source

Announcement

A vulnerability was identified in F5 BIG-IP. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

CVE-2026-94127  is being exploited in the wild. This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Hence, the risk level is rated as High Risk.

Please visit the vendor web-site for more details.

Adobe Monthly Security Update (September 2026)

This is an extract. The publication continues at the source.

Read the original at the source: https://www.hkcert.org/security-bulletin/f5-big-ip-remote-code-execution-vulnerability_20260923

Officially imported this from Hong Kong Computer Emergency Response Team Coordination Centre’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Hong Kong Computer Emergency Response Team Coordination Centre — imported from official source
Official source
https://www.hkcert.org/getrss/security-bulletin RSS
Imported
October 03, 2026 20:41
Versions
1 recorded
Identity
https://www.hkcert.org/security-bulletin/f5-big-ip-remote-code-execution-vulnerability_...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.