Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5423 articles · 221075 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-94127KEVEXPLOITEDPATCHED
f5 · big-ip

BIG-IP APM OAuth vulnerability

Description

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5big-ip21.1.0, 17.5.0, 17.1.0

References

  • https://my.f5.com/manage/s/article/K000162605(vendor-advisory)

Related News (3 articles)

Tier B
CCCS Canada2h ago
AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127
→ No new info (linked only)
Tier B
CCCS Canada5h ago
F5 security advisory (AV26-949)
→ No new info (linked only)
Tier C
VulDB6h ago
CVE-2026-94127 | F5 BIG-IP APM code injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
Hotfix-BIGIP-21.1.0.2.0.30.22-ENGHotfix-BIGIP-17.5.1.9.0.160.12-ENGHotfix-BIGIP-17.1.3.5.0.41.14-ENG
CWECWE-122
PublishedSep 22, 2026
Trending Score141🔥
Source articles3
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-90439
NGINX ngx_http_v3_module vulnerability
Trending: 26
HIGHCVE-2026-78222
NGINX ngx_http_js_module vulnerability
Trending: 6
HIGHCVE-2026-66842
BIG-IP and BIG-IQ Configuration utility vulnerability
Trending: 6
HIGHCVE-2026-18329
NGINX ngx_http_js_module vulnerability
Trending: 6
HIGHCVE-2026-78689
NGINX ngx_http_js_module vulnerablility
Trending: 5

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Added to CISA KEV
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026
Actively Exploited
Sep 22, 2026
Patch Available
Sep 22, 2026