CISA added CVE-2026-94127, a critical heap-based buffer overflow in F5 BIG-IP APM that allows unauthenticated remote code execution, to its Known Exploited Vulnerabilities catalog on 2026-09-22 with a three-day remediation deadline.
What Is It
CVE-2026-94127 is a heap-based buffer overflow (CWE-122) in F5 BIG-IP Access Policy Manager. When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution. F5 rates it CVSS v3.1 9.8 (CRITICAL, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVSS v4.0 9.3. No authentication, no privileges, and no user interaction are required.
Why It Matters
CISA's KEV listing confirms active exploitation, and CISA's SSVC assessment marks the vulnerability as exploitation "active," "automatable: yes," with "total" technical impact. The action due date is 2026-09-25; three days after the catalog addition, an unusually short window. Known ransomware campaign use is listed as Unknown. The KEV entry also flags forensic triage as required, meaning CISA expects defenders to check for prior compromise, not just patch.
What's Vulnerable
F5 lists BIG-IP with the APM module affected in these branches:
- 21.1.0, fixed in
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG - 17.5.0, fixed in
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG - 17.1.0, fixed in
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
BIG-IP systems running in Appliance mode are also vulnerable. This is a data plane issue with no control plane exposure. Software versions past End of Technical Support were not evaluated.
Patch Status
F5 has published fixes in the engineering hotfixes above (F5 article K000162605). CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's Forensics Triage Requirements; follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure.
Per CISA's notes, apply the vendor-provided iRule as a temporary mitigation to allow for proactive forensic triage, then install the final vendor patch as soon as possible.
Sources
- F5 Security Advisory K000162605; https://my.f5.com/manage/s/article/K000162605
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-94127
- NVD, CVE-2026-94127, https://nvd.nist.gov/vuln/detail/CVE-2026-94127
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk