What is confirmed
F5 published advisory K000162605 on 22 September for CVE-2026-94127. It describes a memory corruption issue in BIG-IP APM that may allow unauthenticated remote code execution and says it has learned of exploitation.
CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 22 September. Exposure requires a virtual server configured with both an APM access policy and an OAuth profile operating as an authorisation server.
What it means
Not every BIG-IP deployment or OAuth client is vulnerable. The combined profiles and BIG-IP version must be checked before concluding exposure.
The issue concerns the data plane of an edge device; a public URL check cannot confirm patch status or exclude compromise.
What to do
Inventory APM virtual servers and OAuth profiles, compare versions against F5 advisory K000162605 and install the appropriate hotfix for each affected branch.
If patching must wait, obtain F5's documented workaround and review available logs and indicators with your incident response team.
IP analysis helps contextualise a log, while inventory, patching and investigation must be done on the F5 device.


