CVE-2026-94127
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: when a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic…
CISA federal remediation date Sep 25
Vulnerabilities · 1h ago
CSIRT Italia, NCSC-NL, and CERT-EU said F5 BIG-IP Access Policy Manager (APM) is being actively exploited in the wild through CVE-2026-94127, a heap-based buffer overflow that can lead to remote code execution. F5’s fixes cover only BIG-IP APM systems with a virtual server that has both an access policy and an OAuth profile.
Attackers send specially shaped traffic into the OAuth login path, which can make the device write past the end of a memory buffer. On an exposed APM instance, that corruption can be turned into code execution before authentication succeeds, so the issue is not just “BIG-IP” in general but the specific management flow that handles login and policy.
For operators, the lasting question is which APM virtual servers actually have that configuration and whether exploitation already left signs behind. Where that setup exists, patching changes the device’s future state; it does not by itself answer whether the box was already used as the entry point.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: when a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic…
CISA federal remediation date Sep 25
4 sources covering this story
AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127
F5 BIG-IP: rilevato sfruttamento in rete della CVE-2026-94127
Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-94127, presente in BIG-IP APM.
Kwetsbaarheid verholpen in F5 Networks BIG-IP Access Policy Manager
F5 Networks heeft een kwetsbaarheid verholpen in BIG-IP Access Policy Manager (APM).
Part of the PlainSec briefing for 2026-09-22