F5 BIG-IP APM CVE-2026-94127 (CVSS 9.8): unauth RCE when APM is OAuth Authorization Server — CISA KEV 22 Sep
F5 (CVE published 22 September 2026; advisory K000162605) documents CVE-2026-94127: when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server and BIG-IP APM is configured as an OAuth Authorization Server, specific malicious traffic can lead to unauthenticated remote code execution. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization-server profiles) are not affected. Data-plane issue (no control-plane exposure); Appliance mode is also vulnerable. F5 CVSS 3.1 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVSS 4.0 9.3 Critical. CISA added CVE-2026-94127 to KEV on 22 September 2026 (due 25 September 2026; forensic triage under BOD 26-04); known ransomware campaign use Unknown. Temporary mitigation: vendor-provided iRule, then install final vendor hotfixes. Distinct from desk cards on BIG-IP APM PoisonedRefresh / in-memory PHP webshell malware (Sophos/ESET). Primary: F5 K000162605; metadata: NVD; KEV confirmation: CISA 22 Sep 2026.
- Product
- F5 BIG-IP APM configured as OAuth Authorization Server (access policy + OAuth profile on virtual server)
- Versions
- Affected trains per F5/NVD (before listed ENG hotfixes): 21.1.0 before Hotfix-BIGIP-21.1.0.2.0.30.22-ENG; 17.5.0 before Hotfix-BIGIP-17.5.1.9.0.160.12-ENG; 17.1.0 before Hotfix-BIGIP-17.1.3.5.0.41.14-ENG. Not affected: APM used only as OAuth Client/Resource Server without authorization-server profiles. EoTS versions not evaluated.
- CVSS
- (CVSS 3.1 Critical; F5) / 9.3 (CVSS 4.0 Critical; F5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Inventory BIG-IP APM virtual servers with OAuth Authorization Server profiles; apply vendor iRule temporary mitigation if needed for forensic triage, then install the ENG hotfixes for your train (21.1.0.2.0.30.22 / 17.5.1.9.0.160.12 / 17.1.3.5.0.41.14); reduce internet exposure of APM webtop/OAuth endpoints; follow CISA BOD 26-04 due 25 Sep 2026 for FCEB
Primary: F5 — K000162605 / CVE-2026-94127 BIG-IP APM OAuth Authorization Server RCE · Vendor: F5 MyF5 — K000162605 · CVE: CVE-2026-94127 · NVD — CVE-2026-94127 (F5 CVSS 3.1 9.8); CISA KEV added 22 Sep 2026 (due 25 Sep)
