F5 BIG-IP APM: critical CVE-2026-94127 flaw is already exploited
F5 BIG-IP APM has a heap overflow in TMM rated 9.8 under CVSS v3.1, and exploitation is confirmed. The attack needs no credentials — only network access to a virtual server with an APM access policy and OAuth profile. Affected branches are 21.1.0, 17.5.0–17.5.1 and 17.1.0–17.1.3; hotfixes are available.
- CVSS 9.8: heap overflow in TMM, exploitation confirmed by F5
- Unauthenticated attack requires access to a virtual server with an OAuth profile
- Affected: BIG-IP 21.1.0, 17.5.0–17.5.1 and 17.1.0–17.1.3
- ZoomEye found 59,063 internet hosts with BIG-IP and APM markers
Read next
Security