F5 Product Security Update Advisory (CVE-2026-94127)

F5 Product Security Update Advisory (CVE-2026-94127)

Overview


F5 has released a security update that addresses vulnerability CVE-2026-94127 in BIG-IP APM. This vulnerability is a pre-authentication remote code execution vulnerability caused by a heap-based buffer overflow (memory handling error) in the OAuth authentication server feature of BIG-IP APM.

Affected Versions


The following BIG-IP APM versions are affected:

  • 17.1.0 Through 17.1.3.
  • 17.5.0 Through 17.5.1.
  • 21.1.0.

Resolution


A Vulnerability Patch has been provided via the latest update. The following hotfixes are recommended:

  • Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.Iso.
  • Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.Iso.
  • Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.Iso.

Note


F5 recommended updating to the latest version with the Vulnerability Patch, as outlined on the reference site.