Critical RCE Vulnerability in F5 BIG-IP APM Under Exploitation
Successful exploitation of CVE-2026-94127 may allow unauthenticated remote code execution against affected BIG-IP APM OAuth deployments
Summary
Successful exploitation of CVE-2026-94127 may allow unauthenticated remote code execution against affected BIG-IP APM OAuth deployments
Affected platforms
The following platforms are known to be affected:
F5 BIG-IP
BIG-IP APM (Access Policy Manager)
- 21.1.0
- 17.5.0 – 17.5.1
- 17.1.0 – 17.1.3
Specific configuration requirements are needed for the device to be vulnerable, please see F5's Advisory for more details
Note: F5 does not evaluate vulnerabilities against devices that have reached End of Technical Support (EoTS).
Threat details
Exploitation of CVE-2026-94127
F5 has stated they are aware vulnerability CVE-2026-94127 has been exploited in the wild. The NHS England National CSOC assesses further exploitation as highly likely.
Edge devices like F5 BIG-IP are often internet-facing by design and are highly attractive targets to attackers, and there are an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers. The NHS England National CSOC assesses it is highly likely vulnerabilities discovered in edge devices will continue to be exploited as zero-day vulnerabilities, or shortly after vendor disclosure.
Organisations are strongly encouraged to follow NCSC's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.
Introduction
F5 has released a security advisory to address a critical vulnerability in BIG-IP APM. Successful exploitation could allow an unauthenticated attacker to perform remote code execution on an affected device.
- CVE-2026-94127 - Heap-based Buffer Overflow vulnerability - CVSSv4 Base Score: 9.3
Remediation advice
Affected organisations are encouraged to review the F5 Security Advisory K000162605 and apply the relevant update as soon as possible.
Definitive source of threat updates
Last edited: 23 September 2026 1:18 pm