Vulnerability report

Exploited in the wild Confirmed confidence In CISA KEV

CVE-2026-94127

BIG-IP APM OAuth vulnerability

F5 / BIG-IP · affected before Hotfix-BIGIP-21.1.0.2.0.30.22-ENG

Severity
CVSS 9.3 · Critical
Confidence
Confirmed
Exploit status
Exploited in the wild
EPSS
1.4%
First observed
Last observed

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2026-94127 is an unauthenticated BIG-IP APM OAuth vulnerability. When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code...

Is it exploited?

Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.

Who is affected?

F5 / BIG-IP affected before hotfix-bigip-21.1.0.2.0.30.22-eng.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

BIG-IP APM OAuth vulnerability

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.

Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

F5 Affected
BIG-IP
Before Hotfix-BIGIP-21.1.0.2.0.30.22-ENG Before Hotfix-BIGIP-17.5.1.9.0.160.12-ENG Before Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
View vendor advisory (opens in new tab)
Published
22 Sep 2026
Exploitation Reported
22 Sep 2026
Attack vector
Remote
Complexity
Low
Privileges
None
User interaction
None

Tags

edge cisa

CVE References

Exploitation evidence

Why Previdian marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

F5 Security Advisories

Recorded 22 Sep 2026

A trusted third party reported exploitation.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the Previdian Pro API.

Learn about Pro API access
Source Added
F5 Security Advisories First 2026-09-22 16:21 UTC
CISA 2026-09-22 19:50 UTC
CVE 2026-09-22 20:01 UTC
The Hacker News 2026-09-23 08:31 UTC
TheHackerNews 2026-09-23 09:21 UTC
CERT Polska 2026-09-23 14:22 UTC
Security Affairs 2026-09-23 18:21 UTC
TheRegister 2026-09-23 18:21 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
User-Agents
Callback hosts
0
0
0

Request targets and User-Agents available in Pro. Callback host details available in Enterprise.

Scanner coverage

No scanner integrations recorded yet.

Virtual patch status

No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

No detection artifacts or sensor request patterns are available for this CVE yet.

Check back as sensor telemetry and scanner integrations are updated.

Risk and context

Severity, weaknesses, and research context

CVSS v4.0

9.3 Critical
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS

1.4%

Recent mention · watchTowr

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry.We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce...

Read full advisory

All CVSS Scores

CVSS v4.0 9.3 Critical

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All Mentions

Recent mention · watchTowr

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

watchTowr · 23 Sep 2026

Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry.We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce vulnerabilities - it’

Recent mention · Security Affairs

F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks

Security Affairs · 23 Sep 2026

F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild. The flaw can allow an unauthenticated […]

Recent mention · TheRegister

Someone's attacking a critical 0-day RCE in F5 BIG-IP APM

TheRegister · 23 Sep 2026

Good news: there's a patch. Bad news: both CISA and F5 warn that it's under active exploitation

Recent mention · CERT Polska

Krytyczna podatność w BIG-IP APM

CERT Polska · 23 Sep 2026

Zespół CERT Polska informuje o krytycznej podatności, oznaczonej jako CVE-2026-94127, w module BIG-IP APM (znanym również jako Zero Trust Access) firmy F5.Producent potwierdził, że podatność jest aktywnie wykorzystywana przez atakujących.Podatność dotyczy wirtualnych serwerów ze skonfigurowaną polityką dostępu APM oraz profilem OAuth, działających jako OAuth Authorization Server. Producent nie udostępnił jeszcze szczegółów podatności, ale w przypadku tak skonfigurowanych serwerów nieuwierzytelniony atakujący może zdalnie wykonać dowolny kod, co może skutkować pełnym przejęciem serwera....

Recent mention · Rapid7

CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

Rapid7 · 23 Sep 2026

OverviewOn September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.BIG-IP APM provides identity-aware access control for applications and other corporate resources and can integrate with authentication technologies including OAuth, OpenID Connect, and SAML....

Recent mention · F5 Security Advisories

K000162605: BIG-IP APM vulnerability CVE-2026-94127

F5 Security Advisories · 23 Sep 2026

Security Advisory Description When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. (CVE-2026-94127) Important: We have learned that this vulnerability has been exploited. Impact This vulnerability allows an unauthenticated...

Recent mention · The Hacker News

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

The Hacker News · 23 Sep 2026

Swati KhandelwalSep 23, 2026Vulnerability / Network Security Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes. APM is the BIG-IP module that controls how users reach an organization's applications and networks. The vulnerable setup has an APM access policy and an...

Recent mention · F5 Security Advisories

K12201527: Overview of F5 security notifications

F5 Security Advisories · 22 Sep 2026

Security Advisory Description F5 is making two changes to our approach going forward: hardened releases are moving to a six-week cadence, and we are pausing regular security notifications. For more information, please see this blog: Our first hardened release cycle: What we learned and how we’re changing. F5 discloses security vulnerabilities and security exposures for F5 products in security notifications. 2026 security notifications Older security notifications Note: To be notified about F5 security notifications, subscribe to F5 Security Announcements. These announcements include links...

Timeline

From disclosure to observed exploitation

  1. 18:21 UTC

    KEV confirmed by TheRegister

    Exploitation attested by an external source

  2. 18:21 UTC

    KEV confirmed by Security Affairs

    Exploitation attested by an external source

  3. 14:22 UTC

    KEV confirmed by CERT Polska

    Exploitation attested by an external source

  4. 09:21 UTC

    KEV confirmed by TheHackerNews

    Exploitation attested by an external source

  5. 08:31 UTC

    KEV confirmed by The Hacker News

    Exploitation attested by an external source

  6. 20:01 UTC

    KEV confirmed by CVE

    Exploitation attested by an external source

  7. 19:50 UTC

    Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  8. 16:21 UTC

    Added to Previdian KEV Feed

    High-confidence, third-party attested exploitation

  9. 15:20 UTC

    Added to the Previdian watchlist

    Pro and Enterprise Watch users had 5 hours of early warning before CISA KEV. Also 1 hour before Previdian confirmed it as a KEV.

  10. 14:17 UTC

    CVE published

    Vulnerability disclosed publicly

  11. 17:39 UTC

    CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2026-94127

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2026-94127",
  "confidence": "Confirmed",
  "cvss_score": 9.3,
  "cvss_estimated": false,
  "epss_score": 0.01391,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}