Exploited Vulnerabilities Daily
🌐 English

← All new entries

CVE-2026-94127: F5 BIG-IP APM

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

Vendor
F5
Product
BIG-IP APM
Vulnerability
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
Date added
Sep 22, 2026
CISA due date (U.S. federal agencies)
Sep 25, 2026
Known ransomware campaign use
Unknown
Weakness (CWE)
CWE-122

References

This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.

Last updated: · Catalog version 2026.10.02