What it is
CVE-2026-94127 is an unauthenticated BIG-IP APM OAuth vulnerability. When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code...
Vulnerability report
BIG-IP APM OAuth vulnerability
F5 / BIG-IP · affected before Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-94127 is an unauthenticated BIG-IP APM OAuth vulnerability. When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
F5 / BIG-IP affected before hotfix-bigip-21.1.0.2.0.30.22-eng.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.
Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
F5 Security Advisories
A trusted third party reported exploitation.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| F5 Security Advisories First | 2026-09-22 16:21 UTC |
| CISA | 2026-09-22 19:50 UTC |
| CVE | 2026-09-22 20:01 UTC |
| The Hacker News | 2026-09-23 08:31 UTC |
| TheHackerNews | 2026-09-23 09:21 UTC |
| CERT Polska | 2026-09-23 14:22 UTC |
| Security Affairs | 2026-09-23 18:21 UTC |
| TheRegister | 2026-09-23 18:21 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
1.4%
Recent mention · watchTowr
Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry.We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce...
Read full advisoryCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Recent mention · watchTowr
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)watchTowr · 23 Sep 2026
Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry.We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce vulnerabilities - it’
Recent mention · Security Affairs
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE AttacksSecurity Affairs · 23 Sep 2026
F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild. The flaw can allow an unauthenticated […]
Recent mention · TheRegister
Someone's attacking a critical 0-day RCE in F5 BIG-IP APMTheRegister · 23 Sep 2026
Good news: there's a patch. Bad news: both CISA and F5 warn that it's under active exploitation
Recent mention · CERT Polska
Krytyczna podatność w BIG-IP APMCERT Polska · 23 Sep 2026
Zespół CERT Polska informuje o krytycznej podatności, oznaczonej jako CVE-2026-94127, w module BIG-IP APM (znanym również jako Zero Trust Access) firmy F5.Producent potwierdził, że podatność jest aktywnie wykorzystywana przez atakujących.Podatność dotyczy wirtualnych serwerów ze skonfigurowaną polityką dostępu APM oraz profilem OAuth, działających jako OAuth Authorization Server. Producent nie udostępnił jeszcze szczegółów podatności, ale w przypadku tak skonfigurowanych serwerów nieuwierzytelniony atakujący może zdalnie wykonać dowolny kod, co może skutkować pełnym przejęciem serwera....
Recent mention · Rapid7
CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APMRapid7 · 23 Sep 2026
OverviewOn September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.BIG-IP APM provides identity-aware access control for applications and other corporate resources and can integrate with authentication technologies including OAuth, OpenID Connect, and SAML....
Recent mention · F5 Security Advisories
K000162605: BIG-IP APM vulnerability CVE-2026-94127F5 Security Advisories · 23 Sep 2026
Security Advisory Description When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. (CVE-2026-94127) Important: We have learned that this vulnerability has been exploited. Impact This vulnerability allows an unauthenticated...
Recent mention · The Hacker News
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth ServersThe Hacker News · 23 Sep 2026
Swati KhandelwalSep 23, 2026Vulnerability / Network Security Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes. APM is the BIG-IP module that controls how users reach an organization's applications and networks. The vulnerable setup has an APM access policy and an...
Recent mention · F5 Security Advisories
K12201527: Overview of F5 security notificationsF5 Security Advisories · 22 Sep 2026
Security Advisory Description F5 is making two changes to our approach going forward: hardened releases are moving to a six-week cadence, and we are pausing regular security notifications. For more information, please see this blog: Our first hardened release cycle: What we learned and how we’re changing. F5 discloses security vulnerabilities and security exposures for F5 products in security notifications. 2026 security notifications Older security notifications Note: To be notified about F5 security notifications, subscribe to F5 Security Announcements. These announcements include links...
Timeline
18:21 UTC
Exploitation attested by an external source
18:21 UTC
Exploitation attested by an external source
14:22 UTC
Exploitation attested by an external source
09:21 UTC
Exploitation attested by an external source
08:31 UTC
Exploitation attested by an external source
20:01 UTC
Exploitation attested by an external source
19:50 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
16:21 UTC
High-confidence, third-party attested exploitation
15:20 UTC
Pro and Enterprise Watch users had 5 hours of early warning before CISA KEV. Also 1 hour before Previdian confirmed it as a KEV.
14:17 UTC
Vulnerability disclosed publicly
17:39 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-94127
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-94127",
"confidence": "Confirmed",
"cvss_score": 9.3,
"cvss_estimated": false,
"epss_score": 0.01391,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}