F5 BIG-IP APM CVE-2026-94127: unauthenticated RCE that hardening won't stop
F5 published advisory K000162605 for CVE-2026-94127, a heap-based buffer overflow (CWE-122) in the BIG-IP APM data plane handling OAuth traffic. Rated 9.8 under CVSS v3.1, it lets an unauthenticated attacker execute code; CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-22.
- CVSS 9.8 (v3.1) and 9.3 (v4.0), CWE-122, no credentials or user interaction needed
- Affected: BIG-IP APM 21.1.0, 17.5.0–17.5.1, and 17.1.0–17.1.3
- Appliance mode remains exploitable; restricting the management interface does not help
- F5 shipped engineering hotfixes; CISA added the CVE to KEV on 2026-09-22
Read next
Security