Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-24 · updated: 2026-09-24 · tags: [incident, global] · confidence: high · severity: medium · affected_sectors: [global] · au_impact: true

F5 released engineering hotfixes for CVE-2026-94127, a heap-based buffer overflow in BIG-IP Access Policy Manager (APM) rated 9.8 on CVSS v3.1 and 9.3 on v4.0, and confirmed it is being exploited to run code on BIG-IP systems without authentication. The exposed configuration is narrow but common: an APM access policy and an OAuth authorisation server profile on the same virtual server, with APM issuing access tokens to applications. The narrowness is not comfort — restricting access to the BIG-IP management interface does not mitigate the flaw, because the malicious traffic is sent to the virtual server that receives OAuth traffic itself, and systems running in Appliance mode are vulnerable. Patched branches are 21.1 (Hotfix-BIGIP-21.1.0.2.0.30.22-ENG), 17.5 (Hotfix-BIGIP-17.5.1.9.0.160.12-ENG) and 17.1 (Hotfix-BIGIP-17.1.3.5.0.41.14-ENG). CISA added it to the KEV catalog on 22 September with a 25 September federal remediation deadline; F5, CISA and CERT-EU have published no victim count, attributed actor or targeting detail, and F5 narrowed its own CVE record at 00:45 UTC on 23 September to clarify the authorisation-server role after the KEV and CERT-EU entries described the condition more broadly.

Attribute Detail
Sector Global (Macro)
Date 2026-09-24
Source The Hacker News
Reliability Tier 2
CVEs CVE-2026-94127