CyberzSOC

Publication detail
← Back to advisories & guidance

2026-013: Critical Vulnerability in F5 BIG-IP APM ↗ source

September 22, 2026 CERT-EU Advisory

Summary

CERT-EU recommends taking appropriate actions as soon as possible. The vulnerability CVE-2026-94127, with a CVSS score of 9.8, is a heap-based buffer overflow vulnerability and allow unauthenticated attacker to achieve remote code execution (RCE) The vulnerability affects the following versions of BIG-IP APM if configured with an access policy and an OAuth profile on a virtual server [1]: CERT-EU recommends taking the following actions as soon as possible: 1. Check for signs of compromise (see the compromise assessment section). If any sign of compromise is detected, start the incident response process. If patching cannot be applied immediately, F5 provides an iRule-based mitigation for the affected virtual server.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-94127 9.8 Critical F5 BIG-IP APM F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vu…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.