Updated:
24-Sep-2026
Status:
Active
CVEs:
CVE-2026-94127
Fortra is actively researching a heap-based buffer overflow vulnerability in F5 BIG-IP APM when configured as an OAuth Authorization Server (CVE-2026-94127) that could lead to remote code execution. The primary recommendation is to apply the available hotfixes to affected versions.
Who is affected?
According to the vendor, the following BIG-IP APM versions are vulnerable:
- BIG-IP APM 21.1.0
- BIG-IP APM 17.5.0 - 17.5.1
- BIG-IP APM 17.1.0 - 17.1.3
What can I do?
Apply the following hotfixes to affected versions:
- 21.x - Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso
- 17.5.x - Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso
- 17.1.x - Hotfix-BIGIP 17.1.3.5.0.41.14-ENG.iso
For detailed information, refer to the:
How is Fortra helping me?
Fortra is actively researching this threat to build detection capabilities.
Updates
Fortra has kicked off the Emerging Threats process for this vulnerability. This article will be updated with new information about this vulnerability and related security coverage as it becomes available.
