CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

Summary

A critical heap-based buffer overflow vulnerability (CVE-2026-94127) has been identified in F5 BIG-IP APM when specific access policies and OAuth profiles are configured. This flaw could permit unauthenticated remote code execution.

IFF Assessment

FOE

The vulnerability allows for remote code execution by unauthenticated attackers, posing a significant threat to affected systems.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 25, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in F5 BIG-IP APM enables unauthenticated remote code execution, making it a critical target for attackers. Defenders must prioritize applying vendor-provided mitigations and adhere to CISA's guidance on risk-based patching, especially for internet-facing assets.

Read Full Story →