F5 security advisory (AV26-949)

Serial number: AV26-949
Date: September 22, 2026

As of September 22, 2026, F5 is affected by a vulnerability in the following product:

  • BIG-IP APM
    • Versions 21.1.0 prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
    • Versions 17.5.0 prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
    • Versions 17.1.0 prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG

F5 has reported that CVE-2026-94127 is being exploited in the wild.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Date modified: