CVE-2026-94127
- CVSS
- —
- EPSS
- —
- CISA KEV
- Added 2026-09-22, due 2026-09-25
- Exploitation
- No report
- Public exploits
- 1 repositories
- State
- Unknown
Coverage

Actively exploitedwatchTowr Labs
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)(opens the publisher's site in a new tab)
Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce vulnerabilities - it’

Actively exploitedRapid7
CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM(opens the publisher's site in a new tab)
Overview On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected…

Actively exploitedThe Hacker News
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers(opens the publisher's site in a new tab)
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5…
Actively exploitedCERT-FR
Vulnérabilité dans F5 BIG-IP (23 septembre 2026)(opens the publisher's site in a new tab)
Une vulnérabilité a été découverte dans F5 BIG-IP. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. L'éditeur indique que la vulnérabilité CVE-2026-94127 est activement exploitée. Des indicateurs de compromission sont disponibles dans l'avis de l'éditeur.
Actively exploitedCanadian Centre for Cyber Security
AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127(opens the publisher's site in a new tab)
Number: AL26-022 Date: September 22, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to…
What we observed
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- kev addedcisa-kev