Knox CVE Database
/
CVE-2026-94127
Critical
9.3

CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

Added to the CISA KEV catalog:
September 22, 2026

Overview

BIG-IP APM contains a heap-based buffer overflow in its OAuth Authorization Server processing code. An unauthenticated remote attacker can send crafted OAuth traffic to an affected virtual server and achieve arbitrary code execution on the data plane. Only deployments where APM is configured as an OAuth Authorization Server are affected; systems using APM solely as an OAuth client or resource server are not. F5 has confirmed active exploitation of this vulnerability.

Vulnerability details

Affected vendor
F5
Affected product
BIG-IP APM
Weakness type (CWE)
CWE-122

The flaw is a heap-based buffer overflow (CWE-122) in the APM component that handles OAuth Authorization Server requests. When attacker-supplied input is processed by the OAuth handling code, it writes beyond the bounds of a heap-allocated buffer, corrupting adjacent memory. This class of vulnerability is exploitable because the application trusts the size or content of inbound network data without adequate bounds checking before writing it into a fixed-size heap region. The precondition is specific: an APM access policy and an OAuth authorization server profile must both be configured on the same virtual server.


An attacker with network access to the virtual server's data plane sends specially crafted OAuth traffic, requiring no credentials or prior session. The malformed input triggers the heap overflow, corrupting memory in a way that redirects execution flow and yields unauthenticated remote code execution. The attacker gains full control over confidentiality, integrity, and availability of the affected BIG-IP system. Control plane interfaces are not exposed by this path. F5 has confirmed this vulnerability has been exploited in the wild.

Severity and impact

9.3
Critical
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor BIG-IP APM logs for unexpected process crashes, core dumps, or restarts in the APM OAuth daemon, which may indicate a failed or successful exploitation attempt against the heap overflow.
  • Review virtual server access logs for high volumes of malformed or structurally anomalous OAuth authorization requests from sources outside expected client IP ranges, particularly requests that do not correspond to any registered OAuth client.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 25, 2026

Additional hardening

  • Upgrade BIG-IP APM 17.1.x to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG, 17.5.x to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, and 21.1.x to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG; see References for the full vendor advisory.
  • Restrict network access to the affected virtual server's data plane to known, trusted IP ranges using BIG-IP packet filters or upstream firewall rules, reducing the attacker pool to authorized OAuth clients only.
  • If the OAuth Authorization Server profile is not operationally required, remove it from the virtual server configuration to eliminate the vulnerable code path entirely until patching is complete.
  • Conduct forensic triage of affected systems per CISA guidance, as active exploitation has been confirmed; treat any unpatched internet-exposed instance as potentially compromised.

Key dates

Published (NVD)
September 22, 2026
Added to CISA KEV
September 22, 2026
Remediation deadline
September 25, 2026
Last updated
September 23, 2026

References

Frequently asked questions

Does CVE-2026-94127 affect my FedRAMP authorization?

If F5 BIG-IP APM runs inside your authorization boundary, yes. CVE-2026-94127 is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of September 25, 2026 is already behind you. An unpatched KEV inside a FedRAMP boundary is an assessor finding. An overdue one is a finding your assessor and sponsoring agency can see right now. Remediate it immediately or formally document your mitigation and the delay.

How does Knox help me handle CVE-2026-94127?

Knox does not patch your software. Remediating F5 BIG-IP APM is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. Applying the patch is yours to do. Managing your compliance posture while you do it is not something you have to handle on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a CVE like CVE-2026-94127, that means exposure surfaces during continuous monitoring rather than waiting until an assessor flags it at scheduled review time.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-94127's remediation deadline of September 25, 2026 has passed. What happens now?

If CVE-2026-94127 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out and formally documenting why the deadline was missed is what keeps your authorization intact and the agency relationship clean.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.