F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
BIG-IP APM contains a heap-based buffer overflow in its OAuth Authorization Server processing code. An unauthenticated remote attacker can send crafted OAuth traffic to an affected virtual server and achieve arbitrary code execution on the data plane. Only deployments where APM is configured as an OAuth Authorization Server are affected; systems using APM solely as an OAuth client or resource server are not. F5 has confirmed active exploitation of this vulnerability.
The flaw is a heap-based buffer overflow (CWE-122) in the APM component that handles OAuth Authorization Server requests. When attacker-supplied input is processed by the OAuth handling code, it writes beyond the bounds of a heap-allocated buffer, corrupting adjacent memory. This class of vulnerability is exploitable because the application trusts the size or content of inbound network data without adequate bounds checking before writing it into a fixed-size heap region. The precondition is specific: an APM access policy and an OAuth authorization server profile must both be configured on the same virtual server.
An attacker with network access to the virtual server's data plane sends specially crafted OAuth traffic, requiring no credentials or prior session. The malformed input triggers the heap overflow, corrupting memory in a way that redirects execution flow and yields unauthenticated remote code execution. The attacker gains full control over confidentiality, integrity, and availability of the affected BIG-IP system. Control plane interfaces are not exposed by this path. F5 has confirmed this vulnerability has been exploited in the wild.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If F5 BIG-IP APM runs inside your authorization boundary, yes. CVE-2026-94127 is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of September 25, 2026 is already behind you. An unpatched KEV inside a FedRAMP boundary is an assessor finding. An overdue one is a finding your assessor and sponsoring agency can see right now. Remediate it immediately or formally document your mitigation and the delay.
Knox does not patch your software. Remediating F5 BIG-IP APM is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. Applying the patch is yours to do. Managing your compliance posture while you do it is not something you have to handle on your own.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a CVE like CVE-2026-94127, that means exposure surfaces during continuous monitoring rather than waiting until an assessor flags it at scheduled review time.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If CVE-2026-94127 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out and formally documenting why the deadline was missed is what keeps your authorization intact and the agency relationship clean.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)








