K000162605: BIG-IP APM vulnerability CVE-2026-94127
Checked 29 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · K000162605
K000162605: BIG-IP APM vulnerability CVE-2026-94127
Scope: BIG-IP APM. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
F5 reports an unauthenticated remote code execution vulnerability when BIG-IP APM is configured as an OAuth Authorization Server. F5 states that the vulnerability has been exploited.
Known issues are documented. Affected configurations can allow unauthenticated remote code execution. F5 assigns internal issue ID 2524777 and provides indicators of compromise and a support-provided iRule mitigation.
Install the F5 engineering hotfix for the affected branch. If no fix is listed for the deployed branch, upgrade to a branch with a fix. Contact F5 Support for the mitigation iRule when immediate updating is not possible.
Checked 29 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source