Vendor

F5

F5 news

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability (CVE-2026-94127) is being actively exploited, CISA warns

CISA added CVE-2026-94127 (F5 BIG-IP APM) to its Known Exploited Vulnerabilities catalog on September 22, 2026, which means there is reliable evidence of exploitation in the wild. F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

Why it matters

CISA lists this as exploited in the wild. Unpatched BIG-IP and BIG-IP APM systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing…

Why it matters

CISA lists this as exploited in the wild. Unpatched BIG-IP and Multiple Products systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Actively exploited

All 8 →

F5 BIG-IP APM

F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

Added Sep 22, 2026Fed. due Sep 25, 2026Coverage →

F5 BIG-IP

F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

Added Mar 27, 2026Fed. due Mar 30, 2026
CVE-2023-46747RansomwareCVSS 9.8

F5 BIG-IP Configuration Utility

F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

Added Oct 31, 2023Fed. due Nov 21, 2023

F5 BIG-IP Configuration Utility

F5 BIG-IP Configuration Utility SQL Injection Vulnerability

Added Oct 31, 2023Fed. due Nov 21, 2023
CVE-2022-1388RansomwareCVSS 9.8

F5 BIG-IP

F5 BIG-IP Missing Authentication Vulnerability

Added May 10, 2022Fed. due May 31, 2022

F5 BIG-IP Traffic Management Microkernel

F5 BIG-IP Traffic Management Microkernel Buffer Overflow

Added Jan 18, 2022Fed. due Feb 1, 2022
CVE-2020-5902RansomwareCVSS 9.8

F5 BIG-IP

F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

Added Nov 3, 2021Fed. due May 3, 2022
CVE-2021-22986RansomwareCVSS 9.8

F5 BIG-IP and BIG-IQ Centralized Management

F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

Added Nov 3, 2021Fed. due Nov 17, 2021

Products