Cyber & AI intelligence
Wasteland.
Briefs indexed2807
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-94127 2026-09-22

F5 BIG-IP APM Hit With Critical Unauthenticated RCE — CVE-2026-94127 Now in CISA KEV

"CISA added CVE-2026-94127, a critical heap-based buffer overflow in F5 BIG-IP APM that allows unauthenticated remote code execution, to its Known Exploited Vulnerabilities catalog on 2026-09-22 with a three-day…"

CISA added CVE-2026-94127, a critical heap-based buffer overflow in F5 BIG-IP APM that allows unauthenticated remote code execution, to its Known Exploited Vulnerabilities catalog on 2026-09-22 with a three-day remediation deadline.

What Is It

CVE-2026-94127 is a heap-based buffer overflow (CWE-122) in F5 BIG-IP Access Policy Manager. When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution. F5 rates it CVSS v3.1 9.8 (CRITICAL, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVSS v4.0 9.3. No authentication, no privileges, and no user interaction are required.

Why It Matters

CISA's KEV listing confirms active exploitation, and CISA's SSVC assessment marks the vulnerability as exploitation "active," "automatable: yes," with "total" technical impact. The action due date is 2026-09-25; three days after the catalog addition, an unusually short window. Known ransomware campaign use is listed as Unknown. The KEV entry also flags forensic triage as required, meaning CISA expects defenders to check for prior compromise, not just patch.

What's Vulnerable

F5 lists BIG-IP with the APM module affected in these branches:

BIG-IP systems running in Appliance mode are also vulnerable. This is a data plane issue with no control plane exposure. Software versions past End of Technical Support were not evaluated.

Patch Status

F5 has published fixes in the engineering hotfixes above (F5 article K000162605). CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's Forensics Triage Requirements; follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure.

Per CISA's notes, apply the vendor-provided iRule as a temporary mitigation to allow for proactive forensic triage, then install the final vendor patch as soon as possible.

Sources