ZeroDayAlert

CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

F5 BIG-IP APM Added to KEV 2026-09-22 Federal due 2026-09-25 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

F5 BIG-IP APM is affected when both an access policy and an OAuth profile are configured on the same virtual server. The vulnerability allows unauthenticated remote code execution via a heap-based buffer overflow. The record does not specify which versions of BIG-IP APM are vulnerable, nor does it detail the specific configuration conditions beyond the presence of both policy types.

How to check whether this touches you

  • Inventory your F5 BIG-IP APM appliances and document which are internet-facing or reachable from untrusted networks.
  • For each BIG-IP APM instance, establish whether both an access policy and an OAuth profile are active on any virtual server; check the configuration management interface or review exported configurations.
  • Query BIG-IP APM logs and administrative audit trails for recent configuration changes that introduced or modified OAuth profiles alongside access policies.
  • Establish the running software version of each instance via the administrative UI or API; note that F5 may have backported fixes into maintenance releases.
  • If you cannot access configuration details directly, engage your F5 account team or use F5's vulnerability assessment tools to map your deployment against the stated conditions.

What to do

  1. Immediately classify BIG-IP APM instances with both access policies and OAuth profiles as high priority and escalate to your change advisory board.
  2. Consult F5's vendor guidance (referenced in CISA BOD 26-04) for patch availability and applicability to your version line; do not assume all releases are covered equally.
  3. If patching cannot be applied within the federal remediation window (2026-09-25), implement network segmentation to restrict unauthenticated access to affected virtual servers; document the compensating control in your risk register.
  4. Enable detailed logging on affected BIG-IP APM instances, including authentication attempts, policy evaluations, and OAuth transactions; forward logs to a central store with extended retention.
  5. Schedule a maintenance window and plan for patch deployment; test patches in a staging environment that mirrors your access policy and OAuth configuration before production rollout.

If you find you were exposed

Exploitation of heap-based buffer overflows typically occurs before public disclosure, so assume compromise may predate awareness. Retrieve and analyse BIG-IP APM access logs, authentication logs, and system audit trails from at least 90 days before the public disclosure date (2026-09-22); focus on unusual sequences of unauthenticated requests to affected virtual servers and unexpected process spawning on the appliance. If your log retention is shorter than 90 days, note the gap and prioritise extending retention for future incidents.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-94127 is being exploited. It cannot tell you whether BIG-IP APM is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →