{"id":"CVE-2026-94127","title":"When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)","summary":"When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Aut…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"f5","product":"big-ip_access_policy_manager","affected":["big-ip_access_policy_manager >= 17.0.0, <= 17.1.3","big-ip_access_policy_manager >= 17.5.0, <= 17.5.1","big-ip_access_policy_manager = 21.1.0"],"published":"2026-09-22","updated":"2026-09-23","sourceUpdated":"2026-09-23T14:32:07.910","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94127","references":[{"url":"https://my.f5.com/manage/s/article/K000162605","label":"f5sirt@f5.com"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-94127","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","cve.org","exploit-available"],"epss":0.01293,"epssPercentile":0.69016,"kev":true,"kevDateAdded":"2026-09-22","kevDueDate":"2026-09-25","kevRansomware":false,"exploited":true,"zeroDay":true,"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-22T19:40:08.814686Z"},"ingestedAt":"2026-09-22T15:05:01.088Z","exploits":{"github":2,"githubRepos":["https://github.com/watchtowrlabs/watchTowr-vs-f5-bigip-PreAuth-RCE-CVE-2026-94127","https://github.com/FurkanKAYAPINAR/CVE-2026-94127"],"checkedAt":"2026-09-25T08:21:25.367Z"},"slug":"CVE-2026-94127","body":"## Overview\n\nWhen a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.\n\nImpact:\nThis vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n## Affected\n\n- `big-ip_access_policy_manager >= 17.0.0, <= 17.1.3`\n- `big-ip_access_policy_manager >= 17.5.0, <= 17.5.1`\n- `big-ip_access_policy_manager = 21.1.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"hadal","depthScore":79,"depthScoreParts":{"impact":53.9,"likelihood":0.3,"exploitation":25,"ransomware":0},"changes":[{"seq":209441,"id":"CVE-2026-94127","ts":1790129757120,"field":"zero_day","old":"false","new":"true"},{"seq":209440,"id":"CVE-2026-94127","ts":1790129757120,"field":"kev","old":"false","new":"true"},{"seq":209361,"id":"CVE-2026-94127","ts":1790107880232,"field":"exploit_available","old":"false","new":"true"},{"seq":209360,"id":"CVE-2026-94127","ts":1790107880232,"field":"exploited","old":"false","new":"true"}]}