Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
<div>
<div>
<div><p><strong>Number:</strong> AL26-022<br /><strong>Date:</strong> September 22, 2026</p>
Audience
This Alert is intended for IT professionals and managers.
Purpose
The Canadian Centre for Cyber Security (Cyber Centre) is aware of a critical vulnerability affecting F5 BIG IP Access Policy Manager (APM)Footnote 1.
In response to the vendor advisory released on September 22, 2026, the Cyber Centre released AV26-949 on September 22, 2026Footnote 2.
Tracked as CVE-2026-94127Footnote 3, this vulnerability is a Heap-based Buffer Overflow (CWE-122)Footnote 4 and it affects F5 BIG-IP systems where an APM access policy and an OAuth profile are configured on the same virtual server. Under these conditions, specially crafted malicious traffic may allow an unauthenticated attacker to execute arbitrary code on the affected device, potentially resulting in remote code execution and full system compromise.
F5 has indicated that CVE-2026-94127 is being exploited in the wild.
Suggested actions
The Cyber Centre strongly recommends that organizations running affected F5 BIG‑IP APM deployments upgrade to the following vendor-supported fixed hotfix releases:
| Affected product | Affected versions | Fixed Versions |
|---|---|---|
| BIG IP APM | Versions 17.1.0 prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG | Version 17.1.0 Hotfix-BIGIP-17.1.3.5.0.41.14-ENG |
| BIG IP APM | Versions 17.5.0 prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG | Version 17.5.0 Hotfix-BIGIP-17.5.1.9.0.160.12-ENG |
| BIG IP APM | Versions 21.1.0 prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG | Version 21.1.0 Hotfix-BIGIP-21.1.0.2.0.30.22-ENG |
The Cyber Centre also recommends organizations to:
- Identify vulnerable BIG IP systems that have both an APM access policy and an OAuth profile configured on a virtual server.
- Apply the vendor-provided iRule (contact F5 Support to obtain the iRule)Footnote 1.
- Review access logs for indicators of compromise (IoC), particularly OAuth authentication failures especially in rapid succession or large volumeFootnote 1. Also review administrative accounts, access policies for any signs of suspicious activity.
- Upgrade to a vendor-supported fixed software version as soon as possible.
- Ensure management interfaces are restricted to trusted administrative networks.
- Follow F5 guidance for vulnerability remediation and validation following patch deployment.
Note: Organizations operating Common CriteriaFootnote 5 evaluated configurations should review F5's advisoryFootnote 1 and apply the recommended updates in accordance with their change management and certification requirements.
In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security ActionsFootnote 6 with an emphasis on the following topics:
- Consolidating, monitoring, and defending Internet gateways
- Patch operating systems and applications
- Harden operating systems and applications
- Isolate web-facing applications
Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal, or email [email protected].
References
- Footnote 1
-
K000162605: BIG-IP APM vulnerability CVE-2026-94127
<p><a rel="noreferrer" target="_blank">Return to footnote1 referrer</a></p> </dd> <dt>Footnote 2</dt> <dd> <p><a rel="noreferrer" target="_blank">AV26-949 – F5 security advisory</a></p> <p><a rel="noreferrer" target="_blank">Return to footnote2 referrer</a></p> </dd> <dt>Footnote 3</dt> <dd> <p><a href="https://nvd.nist.gov/vuln/detail/cve-2026-94127" rel="noreferrer" target="_blank">CVE-2026-94127 Detail</a></p> <p><a rel="noreferrer" target="_blank">Return to footnote3 referrer</a></p> </dd> <dt>Footnote 4</dt> <dd> <p><a href="https://cwe.mitre.org/data/definitions/122.html" rel="noreferrer" target="_blank">CWE-122: Heap-based Buffer Overflow</a></p> <p><a rel="noreferrer" target="_blank">Return to footnote4 referrer</a></p> </dd> <dt>Footnote 5</dt> <dd> <p><a rel="noreferrer" target="_blank">Common Criteria – Canadian Centre for Cyber Security</a></p> <p><a rel="noreferrer" target="_blank">Return to footnote5 referrer</a></p> </dd> <dt>Footnote 6</dt> <dd> <p><a rel="noreferrer" target="_blank">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)</a></p> <p><a rel="noreferrer" target="_blank">Return to footnote6 referrer</a></p> </dd>
</div>
Article Link: AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127 - Canadian Centre for Cyber Security