{"type":"bundle","id":"bundle--09392208-7912-54ca-aa00-604645b7dcc0","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--bf54a66f-2282-58e0-b803-93d385c2d117","created":"2026-09-22T20:06:15.209Z","modified":"2026-09-22T20:06:15.209Z","name":"F5 BIG-IP APM OAuth VIP can run attacker code with no login","description":"F5 disclosed CVE-2026-94127 on 2026-09-22: heap overflow RCE on BIG-IP APM when access policy and OAuth share a VIP. Unauthenticated. Appliance mode included. CISA added it to KEV the same day. Fixed by ENG hotfixes Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG. Temporary iRule available via F5 Support for triage before patch.","aliases":["CVE-2026-94127","K000162605","F5 BIG-IP APM OAuth RCE"],"first_seen":"2026-09-22T14:17:42.730Z","last_seen":"2026-09-22T19:02:09.978Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"F5 K000162605","url":"https://my.f5.com/manage/s/article/K000162605"},{"source_name":"CVE-2026-94127 CVE record","url":"https://www.cve.org/CVERecord?id=CVE-2026-94127"},{"source_name":"NVD CVE-2026-94127","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94127"},{"source_name":"CISA KEV catalog 2026.09.22","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-94127-f5-big-ip-apm-oauth-rce-kev"}]}]}