Junglewise Threat Intelligence

CVE-2026-94127: F5 BIG-IP APM heap-based buffer overflow

CVE-2026-94127 · Severity: critical · Exploited in the wild · Published 2026-09-22

Executive brief

F5 BIG-IP APM is a network access and authentication system used to protect corporate resources and manage user access policies. A heap-based buffer overflow vulnerability exists when an access policy and OAuth profile are configured together, allowing unauthenticated attackers to execute arbitrary code remotely, potentially compromising the entire network infrastructure protected by the device.

Technical details

A heap-based buffer overflow exists in F5 BIG-IP APM's OAuth authentication handling when both an access policy and OAuth profile are simultaneously configured on a virtual server. The vulnerability resides in the policy engine's credential processing logic and is reachable over the network without prior authentication. An attacker can send a specially crafted request to the affected virtual server to trigger the buffer overflow, leading to heap memory corruption and remote code execution with the privileges of the BIG-IP process. The vulnerability has been observed actively exploited in the wild, indicating public exploit code or active attack campaigns are operational. Patches should be obtained directly from F5 for affected BIG-IP versions.

Affected products

  • F5 BIG-IP APM

Timeline

  • 2026-09-22: disclosed
  • exploited: Known to be actively exploited in the wild

Related threats