CVE-2026-94127

9.8 CISA KEV

F5 · BIG-IP

A heap-based buffer overflow in F5 BIG-IP APM, when configured as an OAuth Authorization Server, allows unauthenticated attackers to achieve remote code execution via malicious traffic.

Executive summary

This critical vulnerability in F5 BIG-IP allows unauthenticated remote code execution and is currently being actively exploited in the wild.

Vulnerability

This is a heap-based buffer overflow (CWE-122) occurring within the BIG-IP APM module when configured as an OAuth Authorization Server. An unauthenticated attacker can trigger this flaw by sending specially crafted malicious traffic to the affected virtual server.

Business impact

The ability for an unauthenticated attacker to execute arbitrary code on a critical network appliance poses a catastrophic risk to organizational security. Given the CVSS score of 9.8, this flaw grants full system compromise potential, leading to total loss of confidentiality, integrity, and availability for the affected appliance and the traffic passing through it.

Remediation

Immediate Action: Apply the specific vendor-provided hotfixes listed in the F5 security advisory (K000162605) immediately to all affected BIG-IP instances.

Proactive Monitoring: Monitor system logs for unusual traffic patterns targeting OAuth endpoints and review APM access policy logs for unexpected service crashes or restarts.

Compensating Controls: If patching cannot be performed immediately, disable the OAuth Authorization Server profile on vulnerable virtual servers or restrict access to these endpoints via upstream network segmentation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents an extreme risk to the environment due to the combination of unauthenticated remote code execution and documented active exploitation. Organizations must prioritize the deployment of the specified F5 hotfixes across all affected BIG-IP production environments as a matter of urgency to prevent unauthorized system compromise.

More F5 CVEs all →

History

  1. Disclosed CVE record published
  2. Added to CISA KEV confirmed active exploitation
  3. Collected by CVE Brief via github
  4. Analyst report written
  5. Published in the daily brief kev section
  6. Deep Dive published

Sources

Originally found and disclosed by F5, per the CVE Program record.