CISA KEV Alert 22 Sept 2026, 20:31 UTC

CISA Warns of Active Attacks Exploiting Critical F5 BIG-IP Flaw

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalogue on 22 September 2026. The vulnerability affects F5 BIG-IP APM and is a heap-based buffer overflow that can enable unauthenticated remote code execution when an access policy and OAuth profile are configured on a virtual server.

The flaw is a heap-based buffer overflow in the BIG-IP APM component. An unauthenticated attacker may exploit it remotely to execute code on an affected system. The vulnerability has a CVSS score of 9.8 and is rated Critical. The patch status is unknown. F5 has provided a temporary mitigation iRule and advises installing the final vendor patch as soon as possible.

CISA’s KEV listing confirms that attackers are actively exploiting this vulnerability. The available data does not confirm ransomware campaign use. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 25 September 2026. The short deadline reflects the risk associated with internet-exposed BIG-IP APM deployments.

CISA requires organisations to apply mitigations in accordance with F5’s vendor instructions, while complying with BOD 26-04 and CISA’s Forensics Triage Requirements. Organisations should apply the vendor-provided iRule to support proactive forensic triage, then install the final vendor patch as soon as possible. If mitigations are unavailable, applicable BOD 26-04 guidance requires organisations to discontinue use of the product. FCEB agencies are directly affected, but all organisations should review their exposure and patching status.

Consult the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline