Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
SECURITY ADVISORYF5VERIFIED

PUBLISHER UPDATE · K000162605

K000162605 release notes and known issues

K000162605: BIG-IP APM vulnerability CVE-2026-94127

Scope: BIG-IP APM. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

F5 reports an unauthenticated remote code execution vulnerability when BIG-IP APM is configured as an OAuth Authorization Server. F5 states that the vulnerability has been exploited.

Improvements and security content

  • F5-provided engineering hotfixes for affected BIG-IP APM branches.
  • F5-provided indicators of compromise and an iRule mitigation through F5 Support.

Known issues

Publisher statement

Known issues are documented. Affected configurations can allow unauthenticated remote code execution. F5 assigns internal issue ID 2524777 and provides indicators of compromise and a support-provided iRule mitigation.

Affected products and versions

Products

  • BIG-IP APM

Affected versions

  • 21.1.0
  • 17.5.0 through 17.5.1
  • 17.1.0 through 17.1.3

Fixed versions or updates

  • Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso
  • Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso
  • Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso

Recommended action

Install the F5 engineering hotfix for the affected branch. If no fix is listed for the deployed branch, upgrade to a branch with a fix. Contact F5 Support for the mitigation iRule when immediate updating is not possible.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

F5VERIFIED

K000162605: BIG-IP APM vulnerability CVE-2026-94127

Checked 29 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source