Skip to content
NCSA - Cybersecurity Advisories - الوكالة الوطنية للأمن السيبراني

NCSA - Cybersecurity Advisories - الوكالة الوطنية للأمن السيبراني

Ncsa.Qa • September 23, 2026

On 22 September 2026, F5 disclosed CVE-2026-94127, a critical vulnerability affecting BIG-IP Access Policy Manager (APM), and confirmed that it is being actively exploited in the wild. The vulnerability may allow an unauthenticated remote attacker to execute arbitrary code on affected BIG-IP systems.

CVE-2026-94127 is a heap-based buffer overflow vulnerability (CWE-122) affecting F5 BIG-IP APM. The vulnerability affects systems where an Acess Policy Manager (APM) access policy and an OAuth profile are configured on the same virtual server. Specially crafted traffic may allow an unauthenticated remote attacker to execute arbitrary code on the affected BIG-IP device. The vulnerability has a CVSS v3.1 score of 9.8 (Critical). Exploitation can occur remotely with low attack complexity and requires no privileges or user interaction, with potentially high impact on integrity, and availability. F5 released hotfixes for affected systems and confirmed that the vulnerability is being actively exploited in the wild as a zero-day. CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog on 22 September 2026, further highlighting the urgency of applying the available security updates.

Apply vendor-recommended patches and mitigations in accordance with vendor instructions, ensuring alignment with NCSA’s Qatar National Vulnerability Management Guidelines, Version 1.0 including its risk-based prioritization and Reference SLA Matrix. Stakeholders are responsible for evaluating the affected asset’s criticality and internet exposure, prioritizing remediation accordingly, and ensuring that vulnerabilities are remediated within the applicable NCSA timeframe. Where immediate remediation is not feasible, the vulnerability should be formally tracked and managed through the organization’s vulnerability and risk management process until remediation is completed.

We use cookies to enhance your experience on our website. Click 'Accept All' to consent.

Extracted Entities

Attack Types (1)

Countries (1)

Platforms (1)