CVE-2026-94127
Received Received - Intake

Remote Code Execution in F5 BIG-IP APM

Vulnerability report for CVE-2026-94127, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: F5 Networks

Description

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
f5 bigt_ip *-*
f5 bigt_ip_apm *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in F5 BIG-IP APM when an access policy and OAuth profile are configured on a virtual server. Malicious traffic can exploit this to execute arbitrary code remotely on the system.

Impact Analysis

An unauthenticated attacker could gain full control over the affected BIG-IP system, potentially leading to data breaches, service disruption, or further network compromise. Appliance mode systems are also at risk.

Compliance Impact

This RCE vulnerability could lead to unauthorized access to sensitive data, violating GDPR (data protection) and HIPAA (health information security) requirements. Organizations may face compliance penalties if exploited.

Mitigation Strategies

Apply the latest security patches from F5 for BIG-IP APM and OAuth profile configurations. Disable or restrict access to vulnerable virtual servers until patched. Monitor network traffic for unusual patterns targeting APM or OAuth endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94127. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart