important · Edge — BIG-IP
An unauthenticated request can execute code on an actively exploited BIG-IP APM virtual server.
Affects
F5 BIG-IP Access Policy Manager, an enterprise access and authentication gateway appliance.
Exposure is limited to virtual servers combining an APM access policy with an OAuth profile; there, crafted unauthenticated traffic triggers a heap overflow and arbitrary code execution.
Detail and 5 sources
F5 confirms exploitation in the wild, and CISA included CVE-2026-94127 in KEV.
The published remediation does not revoke pre-fix BIG-IP images; they remain accepted.
Sources
ResearchAktiivisesti hyväksikäytetty kriittinen haavoittuvuus F5 BIG-IP Acces Policy Manager - tuotteessa | TraficomResearchF5 BIG-IP: rilevato sfruttamento in rete della CVE-2026-94127 (AL08/260922/CSIRT-ITA) – CSIRT ToscanaVendorCERT-EU - Critical Vulnerability in F5 BIG-IP APMSecondaryAL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127Secondaryhttps://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json