Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve, kev] · confidence: high · severity: critical · affected_sectors: [technology, finance, government] · au_impact: true

CVE-2026-94127

Summary

A heap-based buffer overflow in F5 BIG-IP APM that allows an unauthenticated attacker to achieve remote code execution, scored CVSS 3.1 9.8.

Details

NVD records CVE-2026-94127 at CVSS 3.1 9.8 (Critical) — vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — with the CVSS 4.0 base score at 9.3. The trigger condition is specific and worth checking against configuration: when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, "specific malicious traffic can lead to Remote Code Execution". F5 notes the BIG-IP system in Appliance mode is also vulnerable, and frames it as a data plane issue with no control plane exposure.

Exploitation and defensive guidance

CISA added CVE-2026-94127 to the Known Exploited Vulnerabilities catalog on 22 September 2026, alongside the three other entries listed at that add, on evidence of active exploitation. F5's advisory, accessed through the MyF5 support portal (article K000162605), carries the fixed-version matrix; administrators should confirm current APM and OAuth-profile configuration before scheduling, because the exposure is configuration-dependent rather than universal.

Australian Significance

BIG-IP APM is the component that brokers authenticated remote access into corporate applications, so an unauthenticated RCE on a data plane puts the access-broker itself inside the blast radius rather than at its edge. For Australian entities under APRA CPS 234 and SOCI Act obligations, the operative question is whether the appliance sits in front of externally reachable applications with an APM access policy and OAuth profile configured — the precise combination F5 names.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-09-23.md