CVE Tools

CVE-2026-94127

BIG-IP APM OAuth vulnerability

Published: Sep 22, 2026Updated: Sep 23, 2026 Sources: CVE List NVDCWE-122

Description

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

In plain language

AI Act now

BIG-IP systems using APM as an OAuth Authorization Server are at critical risk and need urgent action.

Executive summary

Unauthenticated network-based remote code execution in F5 BIG-IP APM caused by a CWE-122 memory error when an access policy and OAuth Authorization Server profile are configured on a virtual server.

If affected, business impact
Full BIG-IP takeoverCustomer traffic interceptionService disruptionSensitive data exposureRansomware risk

What to do now

  1. Check whether each BIG-IP virtual server uses APM with both an access policy and an OAuth profile configured as an OAuth Authorization Server.
  2. If it does, identify the BIG-IP software branch currently installed and assess whether the affected virtual server is exposed to untrusted networks.
  3. Install the applicable F5 hotfix: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, or Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.
  4. If the hotfix cannot be installed immediately, open an F5 support ticket to request the available iRule workaround.
  5. Preserve relevant BIG-IP logs and have IT investigate the device for suspicious activity.
Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Sep 22, 2026
Remediation due:Sep 25, 2026

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Official Patch Available
Workaround Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Privilege Escalation
View detailed technique mapping

References

5

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-94127 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store