RAPID 7 reports that F5 published an advisory on 22 September 2026 for CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8 and could allow an unauthenticated attacker with network access to an affected virtual server to achieve remote code execution by sending specially crafted traffic.
It is not exposed by a default configuration: exploitation requires a virtual server configured with both an APM access policy and an OAuth profile. The flaw affects the data plane, not the BIG-IP control plane, and BIG-IP systems operating in Appliance mode are also affected.
F5 lists affected release trains as BIG-IP 21.1.0, 17.5.0 and 17.1.0, with fixes provided in Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG respectively. CVE-2026-94127 was added to CISA’s Known Exploited Vulnerabilities catalogue on 22 September, although Rapid7 says a publicly available proof of concept had not been confirmed.
Organisations should identify virtual servers using the required APM and OAuth combination and apply the relevant hotfix as soon as feasible, particularly where the service is reachable from untrusted networks. Customers unable to update immediately should contact F5 Support for its iRule workaround and implementation guidance.