F5 security advisory (AV26-949)
Canada's Cyber Centre warns F5 BIG-IP APM flaw CVE-2026-94127 is being exploited in the wild.
The Canadian Centre for Cyber Security issued advisory AV26-949 on September 22, 2026, for an F5 BIG-IP APM vulnerability. CVE-2026-94127 affects BIG-IP 21.1.0 through hotfix 21.1.0.2.0.30.22, 17.5.0 through hotfix 17.5.1.9.0.160.12, and 17.1.0 through hotfix 17.1.3.5.0.41.14. F5 reported the flaw is being exploited in the wild. Administrators are urged to review F5 article K000162605 and apply updates.
- CVE-2026-94127 in BIG-IP APM is exploited in the wild.
- Affected branches include BIG-IP 21.1, 17.5, and 17.1.
- Canadian Cyber Centre advisory AV26-949 urges administrators to patch.
Vulnerabilities mentionedAll →
- CVE-2026-941279.32%Unauthenticated Heap-Overflow RCE in F5 BIG-IP APM with OAuth Profilepublished · F5 BIG-IP (Access Policy Manager) KEV PoC ×2
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article76 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-949
Date: September 22, 2026
As of September 22, 2026, F5 is affected by a vulnerability in the following product:
- BIG-IP
- Versions 21.1.0 to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
- Versions 17.5.0 to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
- Versions 17.1.0 to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
F5 has reported that CVE-2026-94127 is being exploited in the wild.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/f5-security-advisory-av26-949