F5 BIG-IP APM CVE-2026-94127: an unauthenticated RCE that a hardening setting does not stop
F5 BIG-IP APM CVE-2026-94127: an unauthenticated RCE that a hardening setting does not stop A load balancer can be an attack surface, not only a traffic cop. CVE-2026-94127 in F5 BIG-IP Access Policy Manager (APM) shows why that distinction matters at the edge of the network. What the vulnerability is F5 published advisory K000162605 for CVE-2026-94127 on 2026-09-22, and CISA added the CVE to its…
The F5 BIG-IP Access Policy Manager (APM) has a critical vulnerability, CVE-2026-94127, which allows unauthenticated remote code execution (RCE) via a heap-based buffer overflow in the data plane path handling OAuth traffic. This flaw does not require any credentials or user interaction and affects specific BIG-IP deployments where APM is used as an OAuth client or resource server.
F5 has released hotfixes for affected versions, but the vulnerability cannot be mitigated by Appliance mode or restricting the management interface. Enterprises should prioritize identifying and patching affected BIG-IP APM virtual servers that combine an access policy with an OAuth authorization server profile and consider inventorying and securing these instances as a top priority.
Brief written by urgent.news from Dev.to's own syndicated text. Machine-written — may contain errors; check the original before relying on it.