www.rapid7.com 23 Sept 2026, 08:43 UTC

F5 BIG-IP Flaw Enables Unauthenticated Remote Code Execution

F5 BIG-IP Flaw Enables Unauthenticated Remote Code Execution
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

RAPID 7 reports that F5 published an advisory on 22 September 2026 for CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8 and could allow an unauthenticated attacker with network access to an affected virtual server to achieve remote code execution by sending specially crafted traffic.

It is not exposed by a default configuration: exploitation requires a virtual server configured with both an APM access policy and an OAuth profile. The flaw affects the data plane, not the BIG-IP control plane, and BIG-IP systems operating in Appliance mode are also affected.

F5 lists affected release trains as BIG-IP 21.1.0, 17.5.0 and 17.1.0, with fixes provided in Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG respectively. CVE-2026-94127 was added to CISA’s Known Exploited Vulnerabilities catalogue on 22 September, although Rapid7 says a publicly available proof of concept had not been confirmed.

Organisations should identify virtual servers using the required APM and OAuth combination and apply the relevant hotfix as soon as feasible, particularly where the service is reachable from untrusted networks. Customers unable to update immediately should contact F5 Support for its iRule workaround and implementation guidance.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline