Skrevet av:

CVE-2026-94127 is a critical heap-based buffer overflow in F5 BIG-IP Access Policy Manager (APM) that can allow an unauthenticated attacker to achieve remote code execution (RCE).

The vulnerability has a CVSS v3.1 score of 9.8 (Critical) and should be treated as a high-priority vulnerability due to confirmed exploitation.

Immediate attention should be given to systems with virtual servers configured with both an APM access policy and an OAuth profile.

mnemonic's Threat Intelligence assessment of CVE-2026-94127

F5 reports that CVE-2026-94127 has been exploited as a zero-day and is being actively exploited in the wild.

At the time of writing, no public proof-of-concept (PoC) has been observed, and the current scale and post-exploitation activity remain unknown. However, the absence of public exploit code and reported attacker campaigns does not materially reduce the risk, as working exploit capability has already been observed.

Given the unauthenticated RCE, network accessibility and security-critical role of BIG-IP devices, affected Internet-facing systems should be considered at elevated risk of compromise until the hotfix has been applied or the iRule mitigation implemented.

Systems affected by CVE-2026-94127

The vulnerability affects the BIG-IP data plane, meaning exposure of the management interface is not required. Exploitation requires a virtual server configured with both an APM access policy and an OAuth profile.

Affected BIG-IP APM branches include:

  • 21.1.x prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
  • 17.5.x prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
  • 17.1.x prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG

F5 notes that End-of-Technical-Support versions were not evaluated and should not be assumed unaffected.

Recommendations for organisations with F5 BIG-IP APM systems

 

Questions concerning CVE-2026-94127?