Skip to content
Critical RCE Vulnerability in F5 BIG-IP APM Exploited

Critical RCE Vulnerability in F5 BIG-IP APM Exploited

First seen 22 Sep 2026, 21:25 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 22:55 UTC
  • CVE-2026-94127 allows RCE via crafted traffic on F5 BIG-IP systems.
  • Active exploitation confirmed; CISA added it to the KEV catalog on the publication date.
  • Immediate patching is essential to mitigate risks associated with this vulnerability.

A newly disclosed vulnerability, CVE-2026-94127, affects F5 BIG-IP systems configured with APM and OAuth profiles, allowing unauthenticated remote code execution (RCE) via crafted network traffic. This vulnerability is particularly dangerous for internet-facing deployments, including identity gateways and remote-access portals. The BIG-IP system in Appliance mode is also impacted, and exploitation can lead to credential theft and traffic manipulation. The vulnerability was added to the CISA KEV catalog on the same day it was published, indicating active exploitation in the wild. Administrators are urged to apply vendor hotfixes immediately or restrict access to affected virtual servers. The risk is exacerbated by the low-precondition attack vector, making automated exploitation feasible. Monitoring for unusual OAuth requests and appliance behavior is critical for detection and response.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
CVE-2026-94127 published
F5 disclosed a critical RCE vulnerability affecting BIG-IP systems with APM and OAuth configurations.
Redpacketsecurity
2026-09-22
CVE added to CISA KEV
CISA included CVE-2026-94127 in its Known Exploited Vulnerabilities catalog due to active exploitation.
Cve

More articles in this cluster (2)

Following this threat?

Track CVE-2026-94127 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed