CVE-2026-94127
F5 BIG-IP APM heap overflow in OAuth request handling -> unauthenticated RCE (zero-day, exploited in the wild)
- Severity
- critical
- Affected product
- F5 BIG-IP
- Affected versions
- F5 BIG-IP all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 1% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-09-23
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the F5 BIG-IP appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-23 (/daily-cve), CVSS 9.3, CISA KEV. Affected branches per the vendor advisory: 21.1.0, 17.5.0-17.5.1, 17.1.0-17.1.3; fixed only by engineering hotfixes (Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, -17.5.1.9.0.160.12-ENG, -17.1.3.5.0.41.14-ENG), so there is no GA version a `fixed_in`/`lt` could name. DELIBERATELY NOT VERSION-GATED, and that is the whole judgement on this row: the bug needs an APM access policy AND an OAuth profile bound to the virtual server, a configuration a version number cannot see. A `ge`/`le` gate on 17.1.x would fire `firm` on every BIG-IP in that branch including the majority that run no APM at all - a false positive on a healthy appliance, which costs more than the CVE is worth. It rides the advisory arm, which names it on any fingerprinted BIG-IP and says confirm the patch level. The fingerprint itself was widened for this row: appliances.json now also probes /pre/config.php?version=2.0, the APM pre-logon config endpoint, so an APM box whose /tmui/ is locked down is still identified. Reference: labs.watchtowr.com F5 BIG-IP unauth heap-overflow to RCE writeup.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →