CISA Adds Critical F5 BIG-IP APM Flaw to Actively Exploited Vulnerabilities
The CVE-2026-94127 vulnerability in F5 BIG-IP APM enables unauthenticated remote code execution under a specific configuration. F5 has released hotfixes, and CISA has added the flaw to its KEV catalog.

CVE-2026-94127 in F5 BIG-IP APM was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026, placing it among flaws with known active exploitation. It is a critical heap-based buffer overflow vulnerability with a CVSS score of 9.8, for which F5 has released fixes.
The flaw affects the Access Policy Manager (APM) component in BIG-IP systems. Under an affected configuration, an unauthenticated remote attacker may execute code on the device. According to CERT-EU, F5 confirmed that the vulnerability is being exploited in the wild.
CVE-2026-94127: Who Is Affected
Exploitation requires more than simply having APM present. An APM access policy and an OAuth profile must be configured on the same virtual server. CERT-EU lists the following affected BIG-IP APM branches:
- 17.1.0 through 17.1.3,
- 17.5.0 through 17.5.1,
- 21.1.0.
Administrators should therefore verify not only the system version but also the specific virtual-server deployment and the combination of these functions. CERT-EU recommends immediately deploying the relevant hotfix from F5.
Remote Code Execution on the Data Plane
CVE-2026-94127 is a heap-based buffer overflow flaw. According to the available information, it affects the device’s data plane, not exposure of the control plane.
The risk is particularly significant for organizations that have BIG-IP APM configured this way and accessible from the internet. APM controls access to applications, and successful remote code execution on such a network device could give an attacker a foothold at the edge of the corporate network.
F5 Releases Hotfixes as CISA Tracks Active Exploitation
Being added to the KEV catalog means that CISA has evidence of exploitation. In this case, F5 also confirmed it, as CERT-EU reports. Organizations should therefore not defer the fix until their regular update cycle and should deploy the hotfix intended for their supported product branch.
Available official materials do not publicly provide details about the attackers, the scope of the campaign, the exploit chains used, or specific compromised organizations. No compromise indicator specific to CVE-2026-94127 has been published either.
Alongside applying the fix, operators should examine their devices using their own forensic procedures and monitor additional materials from F5 and government CERT teams. Any publication of technical details, detection guidance, or compromise indicators will be particularly important.
Sources
- F5 – Vendor security advisory for CVE-2026-94127 and available fixes.
- CISA Known Exploited Vulnerabilities Catalog – Addition of CVE-2026-94127 to the catalog of vulnerabilities with known active exploitation and the nature of the impact.
- CERT-EU Security Advisory 2026-013 – Confirmed active exploitation, affected versions, CVSS 9.8, and a recommendation to deploy the hotfix immediately.
- Canadian Centre for Cyber Security AL26-022 – Independent government confirmation of the affected APM and OAuth profile configuration and the nature of the CWE-122 flaw.
Verified and updated: September 23, 2026 06:19



