Vulnerabilities

F5 BIG-IP APM CVE-2026-94127: exploited zero-day enables RCE

F5 confirms exploitation of CVE-2026-94127 and CISA lists it in KEV. Exposure requires an APM access policy with an OAuth profile; prioritise fixes and checks.

Conceptual illustration: F5 BIG-IP APM CVE-2026-94127: exploited zero-day enables RCE
Conceptual illustration · SecurCheck

What is confirmed

F5 published advisory K000162605 on 22 September for CVE-2026-94127. It describes a memory corruption issue in BIG-IP APM that may allow unauthenticated remote code execution and says it has learned of exploitation.

CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 22 September. Exposure requires a virtual server configured with both an APM access policy and an OAuth profile operating as an authorisation server.

What it means

Not every BIG-IP deployment or OAuth client is vulnerable. The combined profiles and BIG-IP version must be checked before concluding exposure.

The issue concerns the data plane of an edge device; a public URL check cannot confirm patch status or exclude compromise.

What to do

Inventory APM virtual servers and OAuth profiles, compare versions against F5 advisory K000162605 and install the appropriate hotfix for each affected branch.

If patching must wait, obtain F5's documented workaround and review available logs and indicators with your incident response team.

Check a suspicious sign

IP analysis helps contextualise a log, while inventory, patching and investigation must be done on the F5 device.

Sources

  1. F5 — avis officiel K000162605
  2. CISA — ajout au catalogue KEV, 22 septembre
  3. Rapid7 — analyse de configuration et remédiation