← All Advisories

CVE-2026-94127: F5 BIG-IP APM Heap-based

Status: KEV  |  Advisory ID: CVE-2026-94127

Key Details

CVECVE-2026-94127
Affected productsF5 BIG-IP APM
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
Classified asCWE-122 (Heap-based Buffer Overflow)
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-22.
Federal remediation deadline2026-09-25 (CISA KEV, Binding Operational Directive).

What to Know

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-94127