chiprook
← Security
SecuritySeptember 25, 2026, 14:00

F5 BIG-IP APM: critical CVE-2026-94127 flaw is already exploited

F5 BIG-IP APM has a heap overflow in TMM rated 9.8 under CVSS v3.1, and exploitation is confirmed. The attack needs no credentials — only network access to a virtual server with an APM access policy and OAuth profile. Affected branches are 21.1.0, 17.5.0–17.5.1 and 17.1.0–17.1.3; hotfixes are available.

F5 BIG-IP APM: critical CVE-2026-94127 flaw is already exploited
#F5#BIG-IP
Read next
Security

Researchers Flagged AliExpress Phishing Domains Before Registration

Security

Fixing Flock: controls needed after misuse patterns emerge

Security

Gartner: 41% of CISOs hit by AI deepfake voice calls in past year

Security

ZoomEye finds 5.1 million hosts exposing VNC port 5900