← All CVEs NewScan detects
criticalKEV

CVE-2026-94127

F5 BIG-IP APM heap overflow in OAuth request handling -> unauthenticated RCE (zero-day, exploited in the wild)

Severity
critical
Affected product
F5 BIG-IP
Affected versions
F5 BIG-IP all versions before the fix
CISA KEV
Listed as a known exploited vulnerability
EPSS
1% chance of exploitation in the next 30 days
Added to NewScan
2026-09-23
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the F5 BIG-IP appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-23 (/daily-cve), CVSS 9.3, CISA KEV. Affected branches per the vendor advisory: 21.1.0, 17.5.0-17.5.1, 17.1.0-17.1.3; fixed only by engineering hotfixes (Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, -17.5.1.9.0.160.12-ENG, -17.1.3.5.0.41.14-ENG), so there is no GA version a `fixed_in`/`lt` could name. DELIBERATELY NOT VERSION-GATED, and that is the whole judgement on this row: the bug needs an APM access policy AND an OAuth profile bound to the virtual server, a configuration a version number cannot see. A `ge`/`le` gate on 17.1.x would fire `firm` on every BIG-IP in that branch including the majority that run no APM at all - a false positive on a healthy appliance, which costs more than the CVE is worth. It rides the advisory arm, which names it on any fingerprinted BIG-IP and says confirm the patch level. The fingerprint itself was widened for this row: appliances.json now also probes /pre/config.php?version=2.0, the APM pre-logon config endpoint, so an APM box whose /tmui/ is locked down is still identified. Reference: labs.watchtowr.com F5 BIG-IP unauth heap-overflow to RCE writeup.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →