All CVEs
Vulnerability intelligence

CVE-2026-94127

F5 BIG-IP CWE-122

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS Score
9.8
Critical
EPSS — Exploit Probability
Awaiting FIRST.org data · checked 2026-09-22
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Sep 22, 2026 · latest Sep 22, 2026

Coverage timeline

Related CVEs — F5