Apply the engineering hotfixes released by F5 for CVE-2026-94127 immediately. Administrators should verify their BIG-IP APM configuration to determine if APM is functioning as an OAuth authorization server. If APM is not issuing access tokens to applications, the system is not affected by this vulnerability. Monitor F5 security advisories for further updates or full advisory releases.
Quick answers
What is CVE-2026-94127?
Apply the engineering hotfixes released by F5 for CVE-2026-94127 immediately. Administrators should verify their BIG-IP APM configuration to determine if APM is functioning as an OAuth authorization server. If APM is not issuing access tokens to applications, the system is not affected by this vulnerability. Monitor F5 security advisories for further updates or full advisory releases.
How severe is CVE-2026-94127?
critical, CVSS 9.8
Is CVE-2026-94127 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-94127 be mitigated?
Apply the engineering hotfixes released by F5 for CVE-2026-94127 immediately. Administrators should verify their BIG-IP APM configuration to determine if APM is functioning as an OAuth authorization server. If APM is not issuing access tokens to applications, the system is not affected by this vulnerability. Monitor F5 security advisories for further updates or full advisory releases.
CVSS
9.8
Vendor
F5
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
BIG-IP
Mitigation
Apply the engineering hotfixes released by F5 for CVE-2026-94127 immediately. Administrators should verify their BIG-IP APM configuration to determine if APM is functioning as an OAuth authorization server. If APM is not issuing access tokens to applications, the system is not affected by this vulnerability. Monitor F5 security advisories for further updates or full advisory releases.
F5 has released engineering hotfixes for CVE-2026-94127, a critical vulnerability in BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution when APM functions as an OAuth authorization server. The flaw was disclosed on September 22, 2026, and is reported to be actively exploited in the wild. Systems where APM issues access tokens to applications are affected; configurations not using APM as an OAuth server are not at risk.