## Overview
CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026. This vulnerability affects F5 BIG-IP APM when configured as an OAuth Authorization Server. It allows unauthenticated attackers to execute remote code.
## Technical Details
The vulnerability is a heap-based buffer overflow that occurs when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server. Specific malicious traffic can exploit this flaw, leading to remote code execution (RCE). The issue does not affect deployments that use APM solely as an OAuth Client or Resource Server without OAuth authorization server profiles.
## Impact
Exploitation of CVE-2026-94127 can lead to complete system compromise. The BIG-IP system in Appliance mode is also vulnerable. This issue is classified as a data plane vulnerability, meaning it does not expose the control plane. The CVSS score is 9.3, indicating a critical risk.
## Mitigation
F5 recommends that users immediately apply patches to mitigate this vulnerability. Organizations should review their BIG-IP APM configurations to determine if they are using OAuth Authorization Server profiles. If so, they should prioritize patching to prevent potential exploitation.
CSURFACE Threat Sensor