F5 patches exploited CVSS 9.8 flaw in BIG-IP APM
F5 disclosed CVE-2026-94127, a heap-based buffer overflow in BIG-IP Access Policy Manager rated 9.8 that lets an unauthenticated remote attacker execute code on the appliance. The flaw is already being exploited; affected branches are 21.1.0, 17.5.0–17.5.1 and 17.1.0–17.1.3, with hotfixes and an emergency iRule available.
- CVE-2026-94127 is a heap overflow in TMM rated CVSS 9.8
- No credentials needed; leads to remote code execution
- Affected: BIG-IP 21.1.0, 17.5.0–17.5.1, 17.1.0–17.1.3
- ZoomEye found 59,063 internet-visible BIG-IP APM instances
Read next
Security