Skip to content

security_identifier

CVE-2026-94127

Identifier for a heap-based buffer overflow in F5 BIG-IP Access Policy Manager that allows unauthenticated remote code execution over the data plane.

Current clusters

security4 publishers

Attackers are running code on BIG-IP APM boxes configured as OAuth authorization servers

F5 disclosed CVE-2026-94127 on September 22 with hotfixes and evidence of exploitation. It is a data plane heap overflow, so a locked-down management interface still leaves the system exploitable, and federal agencies had until September 25.

Perspective Coverage

4 publishers
Builder
Builder 19%
Operator
Operator 69%
Investor
Investor 12%

Reality

Evidence80
Adoption55
Hype gap+12
Incentives62
Confidence74