CVE-2026-94127(f5 / big-ip_access_policy_manager)

LOWCVSS 9.3 · CRITICALCISA KEV

Signal is active with 29 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-25. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Vendor / third-party advisories
Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • big-ip_access_policy_manager

Threat summary

  • 48 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 29 mentions on most recent observed day (2026-09-23)
  • 48 total mentions across 2 days

Affected systems

Vendors
Products
big-ip_access_policy_manager

1 version affected across 1 product

Deep dive

Activity timeline48 mentions / 2d
07152229Mentions · 2026-09-22: 19Mentions · 2026-09-23: 2909-2209-23
Referenced assets35 URLs
By indicator
Full discourse20 posts
  • The Hacker News@TheHackersNews

    ‼️ WARNING - F5’s BIG-IP APM 0-day is being exploited for unauthenticated RCE. CVE-2026-94127 affects systems where APM acts as an OAuth authorization server. F5 has released hotfixes, and CISA added the flaw to KEV. What to patch and check: https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html

    216140813.1K
    2.4M followersView on X
  • FOFA@fofabot

    ⚠️⚠️ CVE-2026-94127 (CVSS 9.8): Heap overflow in F5 BIG-IP APM OAuth processing -> unauthenticated RCE on internet-facing VPN/identity gateways. Now actively exploited. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJmNS1CSUdJUCI= 🎯1.5M+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="f5-BIGIP" 🔖Refer: https://www.cert.europa.eu/publications/security-advisories/2026-013 #OSINT #FOFA #CyberSecurity #Vulnerability

    110037152.1K
    14.8K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CISA ADDS FOUR KNOWN EXPLOITED VULNERABILITIES — F5 BIG-IP APM CVE-2026-94127 LEADS CISA has updated the Known Exploited Vulnerabilities catalog (2026.09.22, 1721 entries) with four additions. The new lead for operators is F5 BIG-IP APM CVE-2026-94127, which was not previously covered on this channel. • CVE-2026-94127 — F5 BIG-IP APM heap-based buffer overflow • Actively exploited; federal BOD due date 2026-09-25 • Security reporting: unauthenticated RCE when an APM access policy and OAuth profile are on a virtual server (CVSS ~9.8) • Hotfixes available for 21.1.0 / 17.5.x / 17.1.x trains; temporary iRule mitigation until patched Also added (already covered earlier today — not rehashed as standalone posts): • CVE-2026-85102 / CVE-2026-93616 — Check Point • CVE-2026-93952 — Arista VeloCloud Orchestrator ⚠️ Analyst Note: Treat the F5 BIG-IP APM entry as urgent for environments with APM + OAuth on virtual servers. Apply F5’s temporary iRule mitigation where needed, then install the vendor hotfix. CISA alert: https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog F5 advisory: https://my.f5.com/manage/s/article/K000162605 CISA KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog #DDW #DarkWeb #CISA #KEV #F5 #BIGIP #ThreatIntelligence #CyberSecurity

    0111145.1K
    204.8K followersView on X
  • HOL@HashgraphOnline

    Anyone who can reach your F5 login VIP can run code on it with no password when APM and OAuth share that VIP. CISA put this on KEV today. Install the ENG hotfix for your train: https://hol.org/blog/cve-2026-94127-f5-big-ip-apm-oauth-rce-kev https://t.co/PUfSQrAgcI

    04160930
    19.1K followersView on X
  • Canadian Centre for Cyber Security@cybercentre_ca

    #CyberAlert | AL26-022 - Vulnerability Impacting F5 BIG-IP APM Organizations running affected F5 BIG-IP Access Policy Manager (APM) deployments should update affected systems immediately. F5 has indicated CVE-2026-94127 is being exploited in the wild. https://www.cyber.gc.ca/en/alerts-advisories/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127 https://t.co/UtC1N8JE35

    02040686
    34.0K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    An exploited BIG-IP APM vulnerability tracked as CVE-2026-94127 allows RCE attacks. Secure your BIG-IP APM vulnerability deployments with new F5 hotfixes. #F5 #BIGIP #CVE202694127 #Cybersecurity #InfoSec #RCE #Vulnerability https://securityonline.info/big-ip-apm-vulnerability-cve-2026-94127/

    02022381
    13.0K followersView on X
  • Kantorcodes | ℏol/acc@Kantorcodes

    Same-day KEV on F5 BIG-IP APM: if APM and OAuth share a VIP, unauth code exec is on the table. Patch the ENG hotfix or get F5's iRule first. https://hol.org/blog/cve-2026-94127-f5-big-ip-apm-oauth-rce-kev

    01020482
    11.0K followersView on X
  • Diario฿itcoin@DiarioBitcoin

    🚨 F5 corrige CVE-2026-94127 en BIG-IP APM Permite ejecutar código remotamente sin autenticación y ya fue explotada. Afecta configuraciones con política de acceso y perfil OAuth. CISA la incluye en su catálogo KEV. Se recomienda revisar y actualizar. https://t.co/6VUNZABxov

    10010352
    213.1K followersView on X
  • Security Arsenal, LLC@SecurityAr58409

    🔒 #CyberSecurity CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM — Detection, Expo… "On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a heap-based…" 🔗 https://securityarsenal.com/blog/cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm-detection-exposure-audit-and-remediation-guide #CyberSecurity #ThreatIntel #critical #zeroday #cve

    0002015
    34 followersView on X
  • Orion84@Orion84x

    F5 BIG-IP APM is being hit with unauthenticated RCE. CVE-2026-94127 (CVSS 9.8) only bites when APM is an OAuth authorization server with an access policy and OAuth profile on the same virtual server. CISA KEV, federal deadline 25 Sep. https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/

    2000013
    11 followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - F5 BIG-IP APM OAuth Policy Data Plane RCE (CVE-2026-94127) On BIG-IP, when an APM access policy and an OAuth profile are both bound to the same virtual server, specially crafted unauthenticated traffic can hit the data plane policy processing path and trigger remote code execution. Appliance mode is also affected; no control plane exposure. 👉Affected: F5 BIG-IP (APM with OAuth profile on a virtual server)

    0002075
    305 followersView on X
  • zoomeyebot@zoomeyebot

    🚨 F5 BIG-IP APM OAuth Buffer Overflow (CVE-2026-94127) Exploited in the Wild - Unauthenticated RCE Critical Vulnerability Alert! F5 BIG-IP Access Policy Manager (APM) is affected by CVE-2026-94127. 🔍 Identify Targets via ZoomEye: Search Dork: http.body="BIG-IP" && http.body="APM" Exposure: 59.1k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=aHR0cC5ib2R5PSJCSUctSVAiICYmIGh0dHAuYm9keT0iQVBNIg%3D%3D #CVE202694127 #F5 #BIGIP #RCE #Vulnerability #CyberSecurity #ZoomEye

    0001153
    23 followersView on X
  • sunil kumawat@Sunil_kumawat17

    F5 BIG-IP APM: CVE-2026-94127, CVSS 9.8, exploited in the wild. CISA KEV due Sep 25. Unauth RCE on the data plane when a VIP pairs an APM access policy with an OAuth Authorization Server profile.

    1000033
    23 followersView on X
  • Windows Forum@windowsforum

    🚨 F5’s BIG-IP APM OAuth flaw is already under attack—and can mean unauthenticated remote code execution when an access policy and OAuth profile share a virtual server. “Specific config” still means patch now. https://windowsforum.com/news/cve-2026-94127-f5-big-ip-apm-hotfixes-for-actively-exploited-oauth-rce.445557/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #Cybersecurity #F5BigIp #BigIpApm #Cve202694127

    0010043
    1.4K followersView on X
  • VulnTracker@vuln_tracker

    CVE-2026-94127 — F5 BIG-IP APM, CVSS 9.8, actively exploited as a zero-day. Hackers were already using this unauthenticated RCE flaw before F5 shipped a fix. It hits any virtual server with an access policy and OAuth profile configured together, no login, no user interaction, full code execution. Added to CISA's KEV catalog. Remediate by Sep 25, 2026. Details: http://vulntracker.io/cves/CVE-2026-94127 #F5 #BIGIP #CVE #ZeroDay #InfoSec #CyberSecurity

    00010200
    762 followersView on X
  • TwitGri@TwitGri

    🚨 Daily Cyber & IA : F5 BIG-IP APM CVE-2026-94127 exploitée, Check Point corrige une zero-day 9,8, Arista VCO touche 10/10. Côté IA : Claude Opus 5.5 et GPT-6 Sol/Luna arrivent, pendant que l’ONU réunit OpenAI, Anthropic et DeepSeek. #Cyber #IA https://t.co/pKT9gOeqCr

    0001076
    37 followersView on X
  • moton@moton

    Exploited BIG-IP APM Vulnerability CVE-2026-94127 Fixed - https://securityonline.info/big-ip-apm-vulnerability-cve-2026-94127/

    0000156
    756 followersView on X
  • The Circuitry@thecircuitry_

    CVE-2026-94127 now in CISA KEV. Actively exploited F5 BIG-IP APM zero-day. • Heap-based buffer overflow • CVSS v4 9.3 • Unauthenticated RCE when APM policy + OAuth on same virtual server Federal due date 2026-09-25. https://thecircuitry.to/article/cisa-adds-actively-exploited-f5-big-ip-apm-flaw-to-kev-catalog-mud3ryl7 https://t.co/6yeLXKvetH

    1000073
    37 followersView on X
  • NotCVE@notCVE

    CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability CVSS 9.8 · 2 public exploits https://notcve.org/cve/CVE-2026-94127 https://t.co/zuDBL97ldN

    1000050
    72 followersView on X
  • Security Arsenal, LLC@SecurityAr58409

    🔒 #CyberSecurity CVE-2026-94127: F5 BIG-IP APM OAuth Unauthenticated RCE — Detection and Remedia… "NVD has published CVE-2026-94127 as a CVSS 9.8 Critical, network-exploitable…" 🔗 https://securityarsenal.com/blog/cve-2026-94127-f5-big-ip-apm-oauth-unauthenticated-rce-detection-and-remediation-guide #CyberSecurity #ThreatIntel #cve202694127 #critical #cve

    0001065
    34 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appf5big-ip_access_policy_manager---
Appf5big-ip_access_policy_manager21.1.0--

Explore more