---
id: CVE-2026-94127
title: >-
  When a BIG-IP APM access policy and an OAuth profile are configured on a
  virtual server, specific malicious traffic can lead to remote code execution
  (RCE)
summary: >-
  When a BIG-IP APM access policy and an OAuth profile are configured on a
  virtual server, specific malicious traffic can lead to remote code execution
  (RCE). This vulnerability is only present when BIG-IP APM is configured as an
  OAuth Aut…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-122
vendor: f5
product: big-ip_access_policy_manager
affected:
  - 'big-ip_access_policy_manager >= 17.0.0, <= 17.1.3'
  - 'big-ip_access_policy_manager >= 17.5.0, <= 17.5.1'
  - big-ip_access_policy_manager = 21.1.0
published: '2026-09-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T14:32:07.910'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94127'
references:
  - url: 'https://my.f5.com/manage/s/article/K000162605'
    label: f5sirt@f5.com
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-94127
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - cve.org
  - exploit-available
epss: 0.02226
epssPercentile: 0.81996
kev: true
kevDateAdded: '2026-09-22'
kevDueDate: '2026-09-25'
kevRansomware: false
exploited: true
zeroDay: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-22T19:40:08.814686Z'
ingestedAt: '2026-09-22T15:05:01.088Z'
exploits:
  github: 2
  githubRepos:
    - >-
      https://github.com/watchtowrlabs/watchTowr-vs-f5-bigip-PreAuth-RCE-CVE-2026-94127
    - 'https://github.com/FurkanKAYAPINAR/CVE-2026-94127'
  checkedAt: '2026-09-26T09:06:06.857Z'
---

## Overview

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.

Impact:
This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.

 


Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

## Affected

- `big-ip_access_policy_manager >= 17.0.0, <= 17.1.3`
- `big-ip_access_policy_manager >= 17.5.0, <= 17.5.1`
- `big-ip_access_policy_manager = 21.1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
