AllCyberNews

CVE-2026-94127

BIG-IP APM OAuth vulnerability

CVSS 9.3 critical · F5 BIG-IP · published 2026-09-22

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Coverage 1 source

  1. 2026-09-22 CISA Cybersecurity Advisories high CISA Adds Four Known Exploited Vulnerabilities to Catalog

    CISA added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, indicating active exploitation.

Mentioned with

CVE-2026-85102 CVE-2026-93616 CVE-2026-93952

Also covered