F5 Issues Advisory for CVE-2026-94127, Critical RCE Vulnerability in BIG-IP APM

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Critical RCE Vulnerability in F5 BIG-IP APM: CVE-2026-94127

On September 22, 2026, F5 Networks issued a security advisory regarding CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting the F5 BIG-IP Access Policy Manager (APM). This vulnerability has been assigned a CVSS v3.1 score of 9.8, indicating a high severity level. An unauthenticated attacker with network access to an affected virtual server could potentially achieve remote code execution (RCE) by sending specially crafted traffic.

The BIG-IP APM is designed to provide identity-aware access control for applications and corporate resources, integrating with various authentication technologies such as OAuth, OpenID Connect, and SAML. Notably, CVE-2026-94127 is not exposed in a default configuration; exploitation requires a BIG-IP virtual server that has both an APM access policy and an OAuth profile configured. Organizations utilizing this configuration should prioritize remediation, especially since affected BIG-IP systems may process traffic at the network edge.

This vulnerability impacts the data plane but does not expose the BIG-IP control plane. Additionally, BIG-IP systems operating in Appliance mode are also affected.

Affected Versions and Remediation

F5 has identified the following affected release trains and their corresponding fixed hotfixes:

  • BIG-IP 21.1.0: Versions prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
  • BIG-IP 17.5.0: Versions prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
  • BIG-IP 17.1.0: Versions prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG

As of the advisory date, CVE-2026-94127 has been added to the CISA Known Exploited Vulnerabilities Catalog. While a publicly available proof of concept has not been confirmed, organizations should act swiftly to mitigate potential risks.

To remediate the vulnerability, organizations should apply the appropriate F5 hotfix as soon as operationally feasible, particularly if a vulnerable APM and OAuth configuration is accessible from untrusted networks. The recommended updates are as follows:

  • BIG-IP 21.1.0: Update to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG or later.
  • BIG-IP 17.5.0: Update to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG or later.
  • BIG-IP 17.1.0: Update to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG or later.

Administrators should first verify whether a BIG-IP APM access policy and an OAuth profile are configured together on a virtual server, as this configuration is necessary for exposure. For those unable to apply the updates immediately, F5 offers an iRule workaround through their support. Customers are encouraged to open a support case with F5 to obtain the vendor-provided workaround and follow the implementation guidance.

For further details, refer to the full advisory from Rapid7.

Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CIDAR challenge advances passive imaging algorithms for ranging

The recently concluded Computational Imaging Detection and Ranging (CIDAR) challenge, organized by DARPA, aimed to advance passive imaging algorithms for measuring distances up to...

Former Army Soldier Sentenced to 70 Months for Cyber Attacks on AT&T and Snowflake

A former Army soldier, Cameron John Wagenius, has been sentenced to 70 months in prison for a series of cyber attacks and extortion attempts...

Unit 42 Experts Address Common Cybersecurity Myths and Misconceptions

In the ever-evolving landscape of cybersecurity, misconceptions can lead organizations to adopt ineffective strategies that leave them vulnerable to attacks. Insights from Unit 42...

Storm-3168 Threat Actor Exploits Compromised Service Principals for Destructive Azure Attacks

Microsoft Security Research has identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be...