F5 BIG-IP Access Policy Manager (APM) Heap-Based Buffer Overflow Vulnerability
Release Date: 22nd September 2026 (Added 23 September 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-94127 is a critical heap-based buffer overflow vulnerability (CWE-122) in F5 BIG-IP Access Policy Manager (APM). It occurs when a BIG-IP virtual server has both an APM access policy and an OAuth profile configured, and can be triggered by specific malicious network traffic on the data plane (the control plane is not exposed). Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the affected device.
What are the systems affected?
The following BIG-IP releases are affected where an APM access policy and an OAuth profile are configured on the same virtual server:
- BIG-IP 21.1.0 and later, before Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
- BIG-IP 17.5.0 and later, before Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
- BIG-IP 17.1.0 and later, before Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Not affected / patched version:
- BIG-IP 21.1.0 with Hotfix-BIGIP-21.1.0.2.0.30.22-ENG or later, 17.5.0 with Hotfix-BIGIP-17.5.1.9.0.160.12-ENG or later, or 17.1.0 with Hotfix-BIGIP-17.1.3.5.0.41.14-ENG or later
What does this mean?
Successful exploitation may allow attackers to:
- Execute arbitrary code on the affected BIG-IP device without any authentication
- Compromise the confidentiality, integrity, and availability of the BIG-IP device and traffic passing through it
- Pivot from a compromised BIG-IP appliance further into the network it fronts, given BIG-IP's typical placement as a perimeter access and authentication control point
Mitigation process?
CERTVU recommends the following:
-
Apply the vendor hotfix as an emergency change
Apply the hotfix matching your BIG-IP version (Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, or Hotfix-BIGIP-17.1.3.5.0.41.14-ENG) without delay, given confirmed unauthenticated remote code execution in the wild. -
Identify exposed virtual servers
Identify all virtual servers with both an APM access policy and an OAuth profile configured, and treat them as priority remediation targets until patched. -
Apply F5's protective iRule if patching is delayed
Where the hotfix cannot be applied immediately, request and apply F5's protective iRule from F5 Support as a temporary compensating control, and restrict management interface access to trusted networks. -
Treat this as top priority
Reference
- https://my.f5.com/manage/s/article/K000162605
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-94127
- Download advisory (English): F5 BIG-IP Access Policy Manager (APM) Heap-Based Buffer Overflow Vulnerability