Redpacketsecurity Critical RCE Vulnerability in F5 BIG-IP APM Exploited
Article Content
- •CVE-2026-94127 allows RCE via crafted traffic on F5 BIG-IP systems.
- •Active exploitation confirmed; CISA added it to the KEV catalog on the publication date.
- •Immediate patching is essential to mitigate risks associated with this vulnerability.
A newly disclosed vulnerability, CVE-2026-94127, affects F5 BIG-IP systems configured with APM and OAuth profiles, allowing unauthenticated remote code execution (RCE) via crafted network traffic. This vulnerability is particularly dangerous for internet-facing deployments, including identity gateways and remote-access portals. The BIG-IP system in Appliance mode is also impacted, and exploitation can lead to credential theft and traffic manipulation. The vulnerability was added to the CISA KEV catalog on the same day it was published, indicating active exploitation in the wild. Administrators are urged to apply vendor hotfixes immediately or restrict access to affected virtual servers. The risk is exacerbated by the low-precondition attack vector, making automated exploitation feasible. Monitoring for unusual OAuth requests and appliance behavior is critical for detection and response.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-94127 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…