SEPTEMBER 23, 2026
Live Feed
Back to database
Case File

CVE-2026-94127

CRITICAL · CVSS 9.8 EPSS 1.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-09-23

CyberRota Analysis

AI-Generated

The vulnerability affects BIG-IP systems configured with an APM access policy and an OAuth profile, allowing unauthenticated attackers to execute remote code through malicious traffic. This critical issue poses a significant risk, particularly for systems operating in Appliance mode, as it enables exploitation without requiring authentication. Organizations using BIG-IP should prioritize immediate remediation to mitigate potential security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94127
Severity
CRITICAL
CVSS
9.8
EPSS
1.39%
BIG-IP

Original NVD Description

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Related CVEs

Other vulnerabilities affecting the same vendor(s)