Skip to content
CVE Alert: CVE-2026-94127 – F5 – BIG

CVE Alert: CVE-2026-94127 – F5 – BIG

Redpacketsecurity admin September 22, 2026

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

## AI Summary Analysis

**Risk verdict:** This is an actively exploited, remotely reachable compromise risk and should be treated as **priority 1** immediately.

**Why this matters:** Successful exploitation could give an attacker control of a security-critical traffic-management appliance, enabling interception, alteration or disruption of application access. The appliance’s privileged network position also makes it valuable for credential theft, traffic manipulation and follow-on attacks against protected services.

**Most likely attack path:** An attacker sends crafted network traffic to an externally reachable virtual server where APM and OAuth processing are jointly enabled; no credentials or victim interaction are expected. The low-precondition path makes automated scanning and exploitation realistic. Scope is unchanged, so the direct compromise is centred on the appliance, but its connectivity and trust relationships can support lateral movement.

**Who is most exposed:** Internet-facing deployments using APM with OAuth-enabled virtual servers are the highest priority, especially identity gateways, remote-access portals and publishing tiers. Appliance-mode installations should not be excluded from review.

virtual-server and APM logs for malformed, unusually large or repeated OAuth requests.

Correlate anomalous requests with unexpected appliance process launches, crashes or restarts.

Review outbound connections, DNS lookups and configuration changes originating from the appliance.

Alert on administrative activity or new persistence following suspicious web traffic.

Mitigation and prioritisation:

**Treat as priority 1**; apply the vendor hotfix urgently after validating affected APM/OAuth configurations.

If patching is delayed, remove or restrict exposed affected virtual servers and disable unnecessary OAuth/APM combinations.

Request and deploy the vendor-provided iRule workaround through support, with rollback testing.

Preserve logs and appliance state before remediation; perform post-change compromise checks.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

Platforms (1)