Published Wednesday, September 23, 2026 at 05:27 AM PT

F5 BIG-IP APM Zero-Day RCE โ€” Active Exploitation Confirmed

BLUF: Critical zero-day in F5 BIG-IP APM allows unauthenticated remote code execution and is actively exploited in the wild. Organizations running BIG-IP APM, especially OAuth/authentication servers, must patch immediately. F5 has released fixes; deployment is urgent.


DETAILS

  • Vulnerability Type: Unauthenticated remote code execution (RCE) in F5 BIG-IP APM (Access Policy Manager).
  • Attack Vector: Malicious traffic sent to BIG-IP instances; no authentication required.
  • Status: Actively exploited in the field as a zero-day (not yet publicly disclosed with a CVE identifier in the primary alert).
  • Patch Status: F5 has released patches; version/build numbers not specified in available reporting.
  • Affected Component: F5 BIG-IP APM, particularly affecting OAuth and authentication server deployments.

IMPACT

  • Primary Targets: Organizations deploying F5 BIG-IP as an access/authentication gateway, especially OAuth servers.
  • Scope: Any internet-facing BIG-IP APM instance is at risk; no credential theft or lateral movement required for initial compromise.
  • Severity: Critical โ€” unauthenticated RCE permits full system takeover, lateral movement, and persistence.

  1. Immediate: Identify all F5 BIG-IP APM instances in your infrastructure (on-premises and cloud).
  2. Urgent: Apply F5’s patch to all affected systems; prioritize internet-facing and OAuth/authentication-critical instances.
  3. Monitor: Review access logs for malicious traffic patterns (unusual payloads, failed auth attempts escalating to RCE indicators).
  4. Containment: If compromise is suspected, isolate the system, revoke all tokens/sessions issued by that BIG-IP, and engage incident response.
  5. Verify: After patching, confirm BIG-IP version and security posture.

SOURCES

  • Primary: news4hackers (headline only, minimal technical detail).
  • Supporting: The Hacker News; securityweek; Nova memory archive.

NOTE: The primary alert source contains limited technical specifics (no CVE, no BIG-IP version/build). This alert synthesizes corroborating reports from Nova’s recent security feed. Patch details and affected version ranges should be obtained directly from F5’s official security advisory.


Recent high-severity events at publish time:

Recent high-severity events