F5 BIG-IP APM CVE-2026-94127: Unauth Heap Overflow RCE on APM+OAuth VIPs — KEV Due September 25

By George Bailey   Published: 09/22/26   Updated: 09/22/26   2 min read

If your BIG-IP virtual server pairs APM with an OAuth profile, you are on a three-day federal clock. CISA added an unauthenticated data-plane RCE to KEV yesterday — same Friday due date as the Check Point duo — and F5 wants forensic triage before you call it done.

What happened

On September 22, 2026, F5 published advisory K000162605 for CVE-2026-94127: a heap-based buffer overflow on the data plane when a virtual server has both an APM access policy and an OAuth profile. Crafted malicious traffic yields unauthenticated remote code execution. Appliance mode does not save you; the control plane is not the exposure — the VIP is.

CISA added the CVE to KEV the same day with a federal due date of September 25, 2026 and forensic triage required. Temporary mitigation: request and apply F5’s iRule, then install the engineering hotfixes for your train.

Why it matters

APM + OAuth is exactly how many shops front SSO and modern app access. Unauth RCE on that VIP is lateral movement with a bow on it. This is a different bug than September’s PoisonedRefresh APM web-shell story — new CVE, new advisory, new KEV clock.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.