← Back to CVE List
Vulnerability Intelligence Report
BIG-IP APM OAuth vulnerability

CVE-2026-94127

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-122 ↗CWE-122 Heap-based Buffer Overflow

Affected Products & Versions

Vendor Product Affected Versions
F5 BIG-IP 21.1.0 < Hotfix-BIGIP-21.1.0.2.0.30.22-ENG (affected), 17.5.0 < Hotfix-BIGIP-17.5.1.9.0.160.12-ENG (affected), 17.1.0 < Hotfix-BIGIP-17.1.3.5.0.41.14-ENG (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityF5, Inc. · Vendor · USA
Reserved2026-09-20T17:39:19
Published2026-09-22T14:17:42
Patch Date2026-09-22
Last Updated2026-09-22T19:58:23

LINK COPIED TO CLIPBOARD