If your BIG-IP virtual server pairs APM with an OAuth profile, you are on a three-day federal clock. CISA added an unauthenticated data-plane RCE to KEV yesterday — same Friday due date as the Check Point duo — and F5 wants forensic triage before you call it done.
What happened
On September 22, 2026, F5 published advisory K000162605 for CVE-2026-94127: a heap-based buffer overflow on the data plane when a virtual server has both an APM access policy and an OAuth profile. Crafted malicious traffic yields unauthenticated remote code execution. Appliance mode does not save you; the control plane is not the exposure — the VIP is.
CISA added the CVE to KEV the same day with a federal due date of September 25, 2026 and forensic triage required. Temporary mitigation: request and apply F5’s iRule, then install the engineering hotfixes for your train.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters
APM + OAuth is exactly how many shops front SSO and modern app access. Unauth RCE on that VIP is lateral movement with a bow on it. This is a different bug than September’s PoisonedRefresh APM web-shell story — new CVE, new advisory, new KEV clock.
What to do first
- Inventory every BIG-IP VIP with APM access policy and an OAuth profile bound.
- Apply the matching ENG hotfix: 21.1.0.2.0.30.22-ENG, 17.5.1.9.0.160.12-ENG, or 17.1.3.5.0.41.14-ENG.
- If you cannot patch tonight: open an F5 ticket for the interim iRule, and/or unbind OAuth or APM from exposed VIPs where business allows.
- Forensic triage per BOD 26-04 before declaring clean — patch ≠ clean on previously exposed data-plane VIPs.
- Rotate secrets and review APM sessions/policy changes in the pre-patch window.
Details
- CVE: CVE-2026-94127 (CVSS 4.0 base 9.3; heap overflow CWE-122)
- Product: F5 BIG-IP APM (affected trains 21.1 / 17.5 / 17.1 with APM+OAuth on a VIP)
- KEV: Added 2026-09-22; federal due 2026-09-25; forensic triage Yes
- Advisory: https://my.f5.com/manage/s/article/K000162605
- Ransomware use (CISA): Unknown
Hunt / verify
- Confirm installed hotfix build strings match K000162605 for each chassis/vCMP guest.
- List VIPs with both APM and OAuth; anything still unmatched is still exposed.
- Review data-plane logs for anomalous OAuth/APM traffic before the patch window; preserve evidence if compromise is suspected.
Sources
- https://my.f5.com/manage/s/article/K000162605
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-94127
- https://cve.report/CVE-2026-94127
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.