F5 BIG-IP APM: critical CVE-2026-94127 heap overflow in OAuth setups
F5 disclosed CVE-2026-94127 on 22 September 2026, a heap-based buffer overflow in BIG-IP APM rated CVSS 9.8 that can lead to remote code execution. Only deployments where APM acts as an OAuth Authorization Server are affected; CISA added the flaw to its Known Exploited Vulnerabilities catalog.
- CVSS 9.8 (v3.1) and 9.3 (v4.0), CWE-122, F5 internal ID 2524777
- Only virtual servers with an APM access policy and OAuth authorization server profile are exposed
- Affected branches: 21.1.x, 17.5.x and 17.1.x; engineering hotfixes released
- F5 offers an iRule as a temporary mitigation if patching is not possible
Read next
Security