CVE-2026-94127 in F5 BIG-IP APM is listed in the CISA Known Exploited Vulnerabilities catalog (added 2026-09-22). Required action, remediation due date, ransomware association, EPSS score and vendor advisories.
CVE-2026-94127 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added 2026-09-22. F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Wording published by CISA for this catalog entry. It is the baseline action, not a decision about your environment: whether this exposure matters for you depends on where the affected component runs, what it is exposed to and who owns it.
A catalog entry tells you a vulnerability is being exploited somewhere. It does not tell you whether it matters in your estate, who owns the fix, or what evidence an auditor will ask for later. That is the work VulnTrek does: it takes findings from the tools you already run, decides which exposure actually matters, routes it to an owner, keeps remediation human-approved and retains the lineage as evidence.
Sourced from public upstream advisories (CISA KEV, ENISA EUVD, vendor PSIRTs) mirrored daily. Informational only — not a remediation decision, not legal advice, and the absence of a record is not evidence of safety.