Advisory: Critical vulnerability in F5 BIG-IP APM (CVE-2026-94127)
The vulnerability allows an unauthenticated attacker to achieve remote code execution (RCE) and is actively being exploited

Skrevet av:

CVE-2026-94127 is a critical heap-based buffer overflow in F5 BIG-IP Access Policy Manager (APM) that can allow an unauthenticated attacker to achieve remote code execution (RCE).
The vulnerability has a CVSS v3.1 score of 9.8 (Critical) and should be treated as a high-priority vulnerability due to confirmed exploitation.
Immediate attention should be given to systems with virtual servers configured with both an APM access policy and an OAuth profile.
mnemonic's Threat Intelligence assessment of CVE-2026-94127
F5 reports that CVE-2026-94127 has been exploited as a zero-day and is being actively exploited in the wild.
At the time of writing, no public proof-of-concept (PoC) has been observed, and the current scale and post-exploitation activity remain unknown. However, the absence of public exploit code and reported attacker campaigns does not materially reduce the risk, as working exploit capability has already been observed.
Given the unauthenticated RCE, network accessibility and security-critical role of BIG-IP devices, affected Internet-facing systems should be considered at elevated risk of compromise until the hotfix has been applied or the iRule mitigation implemented.
Systems affected by CVE-2026-94127
The vulnerability affects the BIG-IP data plane, meaning exposure of the management interface is not required. Exploitation requires a virtual server configured with both an APM access policy and an OAuth profile.
Affected BIG-IP APM branches include:
- 21.1.x prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
- 17.5.x prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
- 17.1.x prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Recommendations for organisations with F5 BIG-IP APM systems
- Determine whether affected BIG-IP versions are deployed and identify virtual servers using both APM access policies and OAuth profiles
- Review F5's current IoCs and relevant telemetry before patching, particularly for Internet-facing systems
- Patch the applicable F5 hotfix immediately or apply mitigation with F5's interim iRule provided through F5 Support
- Systems showing signs of compromise based on indicators should be handled as potential security incidents. This includes forensic preservation, in-depth investigation and review of credentials and secrets accessible to the appliance
Questions concerning CVE-2026-94127?
