September 27, 2026 · 11 min read
F5 BIG-IP: A 9.8 You Reach Through the Auth Header, With No Credentials
CVE-2026-94127 is a heap overflow in BIG-IP APM that you can reach unauthenticated from the data plane. F5 shipped engineering hotfixes on 22 September and CISA gave US federal agencies three days. The only question that matters for your estate is whether you run APM as an OAuth Authorization Server.
Read more →