Published Wednesday, September 23, 2026 at 05:27 AM PT

BLUF: Critical zero-day in F5 BIG-IP APM allows unauthenticated remote code execution and is actively exploited in the wild. Organizations running BIG-IP APM, especially OAuth/authentication servers, must patch immediately. F5 has released fixes; deployment is urgent.
DETAILS
- Vulnerability Type: Unauthenticated remote code execution (RCE) in F5 BIG-IP APM (Access Policy Manager).
- Attack Vector: Malicious traffic sent to BIG-IP instances; no authentication required.
- Status: Actively exploited in the field as a zero-day (not yet publicly disclosed with a CVE identifier in the primary alert).
- Patch Status: F5 has released patches; version/build numbers not specified in available reporting.
- Affected Component: F5 BIG-IP APM, particularly affecting OAuth and authentication server deployments.
IMPACT
- Primary Targets: Organizations deploying F5 BIG-IP as an access/authentication gateway, especially OAuth servers.
- Scope: Any internet-facing BIG-IP APM instance is at risk; no credential theft or lateral movement required for initial compromise.
- Severity: Critical โ unauthenticated RCE permits full system takeover, lateral movement, and persistence.
RECOMMENDED ACTIONS
- Immediate: Identify all F5 BIG-IP APM instances in your infrastructure (on-premises and cloud).
- Urgent: Apply F5’s patch to all affected systems; prioritize internet-facing and OAuth/authentication-critical instances.
- Monitor: Review access logs for malicious traffic patterns (unusual payloads, failed auth attempts escalating to RCE indicators).
- Containment: If compromise is suspected, isolate the system, revoke all tokens/sessions issued by that BIG-IP, and engage incident response.
- Verify: After patching, confirm BIG-IP version and security posture.
SOURCES
- Primary: news4hackers (headline only, minimal technical detail).
- Supporting: The Hacker News; securityweek; Nova memory archive.
NOTE: The primary alert source contains limited technical specifics (no CVE, no BIG-IP version/build). This alert synthesizes corroborating reports from Nova’s recent security feed. Patch details and affected version ranges should be obtained directly from F5’s official security advisory.
Recent high-severity events at publish time:

