About:
CVE-2026-94127 is a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM) when configured to act as an OAuth Authorization Server.
When a BIG-IP APM access policy and OAuth profile are configured on an affected virtual server, specially crafted malicious traffic can trigger the vulnerability and allow an unauthenticated attacker to execute arbitrary code.
F5 has confirmed active exploitation, and CISA has added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) Catalog. F5 has released engineering hotfixes for affected BIG-IP APM branches and provides a temporary mitigation for organizations unable to patch immediately.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
Identifier: CVE-2026-94127
PoC or Exploitation: Confirmed actively exploited. F5 states directly that it has learned this vulnerability has been exploited. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog.
CVSS Score: 9.8 (Critical, CVSS v3.1)
Update / Patch:
Description:
Mitigation Recommendation: