CVE-2026-94127
BIG-IP APM OAuth vulnerability
Exploited in the wild. In CISA KEV since 2026‑09‑22. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Check whether each BIG-IP virtual server uses APM with both an access policy and an OAuth profile configured as an OAuth Authorization Server.
- If it does, identify the BIG-IP software branch currently installed and assess whether the affected virtual server is exposed to untrusted networks.
- Install the applicable F5 hotfix: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, or Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.
- If the hotfix cannot be installed immediately, open an F5 support ticket to request the available iRule workaround.
- Preserve relevant BIG-IP logs and have IT investigate the device for suspicious activity.
What it is
From the CVE record
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
In plain language
Written by AI from the recordBIG-IP systems using APM as an OAuth Authorization Server are at critical risk and need urgent action.
Unauthenticated network-based remote code execution in F5 BIG-IP APM caused by a CWE-122 memory error when an access policy and OAuth Authorization Server profile are configured on a virtual server.
If you're affected
- Full BIG-IP takeover
- Customer traffic interception
- Service disruption
- Sensitive data exposure
- Ransomware risk
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2026-09-22.
US federal agencies must remediate by 2026-09-25.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
1.3% chance of exploitation activity in the next 30 days, which ranks it in the 69th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
17 events over 1 day, from the signal feeds we watch.
- Patch availableworkaround available, workaround available, workaround available, record updated, record updated, record updated
- Added to CISA KEVworkaround available, workaround available, workaround available, published, weakness classified, att&ck mapped, record updated, record updated, record updated
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Scored 9.8 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
- Privilege EscalationT1068Exploitation for Privilege Escalationhigh confidence
Sources
References in the record
In the news
- Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
- Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
- F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
- Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
- F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for F5, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI