CVE-2026-94127 actively exploited: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

CISA added CVE-2026-94127, a heap-based buffer overflow in F5 BIG-IP APM, to its Known Exploited Vulnerabilities catalogue. F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. Federal agencies must remediate by September 25, 2026.

A heap-based buffer overflow exists in F5 BIG-IP APM when specific access policies and OAuth profiles are active. CISA reports this flaw permits an unauthenticated attacker to achieve remote code execution. The agency has classified this issue as actively exploited in the wild. It remains unclear whether known ransomware campaigns involve this specific defect. The risk targets systems running F5 BIG-IP APM software. Exposure depends on the configuration of virtual servers with both access policies and OAuth profiles. Stakeholders must evaluate the internet exposure of every asset to determine susceptibility. No specific ransomware campaign usage has been confirmed by CISA. Organizations must apply vendor-provided mitigations immediately. Actions should align with CISA BOD 26-04 guidance on prioritizing security updates based on risk. Federal agencies face a remediation deadline of September 25, 2026. If mitigations are unavailable, discontinuing product use follows applicable BOD 26-04 guidance for cloud services.