F5 Product Security Update Advisory (CVE-2026-94127)
Overview
F5 has released a security update that addresses vulnerability CVE-2026-94127 in BIG-IP APM. This vulnerability is a pre-authentication remote code execution vulnerability caused by a heap-based buffer overflow (memory handling error) in the OAuth authentication server feature of BIG-IP APM.
Affected Versions
The following BIG-IP APM versions are affected:
- 17.1.0 Through 17.1.3.
- 17.5.0 Through 17.5.1.
- 21.1.0.
Resolution
A Vulnerability Patch has been provided via the latest update. The following hotfixes are recommended:
- Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.Iso.
- Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.Iso.
- Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.Iso.
Note
F5 recommended updating to the latest version with the Vulnerability Patch, as outlined on the reference site.