RaqibCTI
CVE

CVE-2026-94127

P2
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
F5 · BIG-IP APM
Date added (CISA)
2026-09-22
Remediation due
2026-09-25
Known ransomware use
Not indicated
Remediation priority
P2CISA due date imminent

Description

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

Source: NVD ↗ · CISA KEV Catalog ↗

CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability · RaqibCTI