CVE-2026-94127 is a heap-based buffer overflow (CWE-122) in F5 BIG-IP Access Policy Manager that allows unauthenticated remote code execution, scored CVSS 3.1 9.8 by NVD. CISA added it to the Known Exploited Vulnerabilities catalog on September 22, 2026, the day the CVE record was published, and VulnCheck’s KEV feed reports the same.
The exposure is narrower than “every BIG-IP”. According to the CVE record, only systems where APM is configured as an OAuth Authorization Server are vulnerable. The vulnerable condition is a virtual server that carries both an APM access policy and an OAuth profile.
What the flaw is
The CVE record states that crafted traffic to a virtual server with an APM access policy and an OAuth profile attached can lead to remote code execution. It adds three scoping details that matter for triage:
- Configuration-dependent. APM deployments acting only as an OAuth Client or Resource Server, with no authorization-server profile, are not affected.
- Appliance mode is not a mitigation. BIG-IP systems running in Appliance mode are also vulnerable.
- Data plane only. The CVE record describes this as a data plane issue with no control plane exposure. In our reading, that means the exposure is the traffic-handling virtual server, not the management interface, so restricting management access alone does not reduce it.
The record also notes that software versions past F5’s End of Technical Support were not evaluated. “Not listed” for an EoTS release does not mean “not affected”.
Evidence and confidence
- High confidence — exploitation status, reported independently by CISA KEV and VulnCheck KEV, both dated September 22, 2026.
- High confidence — the CWE-122 classification, which NVD, CVE.org, CISA KEV and VulnCheck all agree on.
- Medium confidence — the 9.8 score and vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), which come from NVD alone in our ingestion. - Not yet available — no FIRST EPSS score is in our ingestion for this CVE yet.
CISA and VulnCheck name the product “BIG-IP APM”; CVE.org names it “BIG-IP”. That is a difference in naming granularity, not a conflict. The description itself confines the flaw to APM.
Why this matters
For BIG-IP owners, the first question is configuration: does any virtual server attach an OAuth Authorization Server profile? If yes, this is a confirmed-exploited, unauthenticated RCE on the traffic path, and it belongs at the top of the queue. If APM is used only as an OAuth client or resource server, the CVE record says the system is not affected by this flaw.
CISA KEV listing places this CVE under Binding Operational Directive 26-04 for in-scope federal agencies, and CISA’s entry references its Forensics Triage Requirements. That makes a compromise check appropriate on any authorization-server deployment that was internet-reachable before patching.
Frequently Asked Questions
What is CVE-2026-94127? A CVSS 9.8 heap-based buffer overflow (CWE-122) in F5 BIG-IP APM that allows unauthenticated remote code execution when APM is configured as an OAuth Authorization Server.
Is CVE-2026-94127 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 22, 2026, and VulnCheck’s KEV feed reports the same.
Is my BIG-IP affected if APM is only an OAuth client? No, according to the CVE record. Deployments using APM strictly as an OAuth Client or Resource Server, without authorization-server profiles, are not affected.
Does Appliance mode protect against it? No. The CVE record states BIG-IP systems in Appliance mode are also vulnerable.
Which version fixes CVE-2026-94127? Our source data does not carry a fixed-version field. F5’s advisory K000162605 lists affected and fixed releases.
Severity, vector and weakness classification from the National Vulnerability Database record for CVE-2026-94127, with configuration scope from the CVE.org record. Exploitation status and the September 22, 2026 catalog date from CISA’s Known Exploited Vulnerabilities catalog entry, independently corroborated by VulnCheck KEV. Vendor advisory: F5 K000162605. Aggregated September 24, 2026. See more vulnerability intelligence.