Skip to main content

Critical RCE Vulnerability in F5 BIG-IP APM Under Exploitation

Successful exploitation of CVE-2026-94127 may allow unauthenticated remote code execution against affected BIG-IP APM OAuth deployments

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation of CVE-2026-94127 may allow unauthenticated remote code execution against affected BIG-IP APM OAuth deployments


Affected platforms

The following platforms are known to be affected:

Threat details

Exploitation of CVE-2026-94127

F5 has stated they are aware vulnerability CVE-2026-94127 has been exploited in the wild. The NHS England National CSOC assesses further exploitation as highly likely.

Edge devices like F5 BIG-IP are often internet-facing by design and are highly attractive targets to attackers, and there are an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers. The NHS England National CSOC assesses it is highly likely vulnerabilities discovered in edge devices will continue to be exploited as zero-day vulnerabilities, or shortly after vendor disclosure.

Organisations are strongly encouraged to follow NCSC's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.


Introduction

F5 has released a security advisory to address a critical vulnerability in BIG-IP APM. Successful exploitation could allow an unauthenticated attacker to perform remote code execution on an affected device.

  • CVE-2026-94127 - Heap-based Buffer Overflow vulnerability - CVSSv4 Base Score: 9.3

Remediation advice

Affected organisations are encouraged to review the F5 Security Advisory K000162605 and apply the relevant update as soon as possible.


Definitive source of threat updates


Last edited: 23 September 2026 1:18 pm