F5 BIG-IP APM Zero-Day RCE โ€” Actively Exploited, Patch Immediately

๐Ÿ›ก๏ธ F5 BIG-IP APM Zero-Day RCE โ€” Actively Exploited, Patch Immediately

Published Wednesday, September 23, 2026 at 05:26 AM PT BLUF: F5 BIG-IP APM contains an unauthenticated remote code execution vulnerability currently exploited in active attacks. Apply patches to all instances immediately. Target priority: OAuth/authentication-facing deployments. DETAILS Zero-day RCE in BIG-IP APM โ€” Attackers can execute arbitrary code without authentication; F5 has confirmed the flaw and released patches Active exploitation confirmed โ€” Multiple threat actors are exploiting this vulnerability in the wild; at least one campaign deployed Linux rootkits following successful compromise OAuth servers at elevated risk โ€” The vulnerability is being weaponized specifically against BIG-IP APM systems deployed as OAuth authentication gateways Exploit timeline unclear โ€” Sources confirm zero-day exploitation occurred before patches became available; specific disclosure/patch release dates not provided in available reporting Patch availability confirmed โ€” F5 has released fixes; specific version numbers and CVE identifier not included in summaries provided IMPACT Scope: Any organization operating vulnerable BIG-IP APM instances, with highest risk for those exposed to untrusted networks or handling OAuth/identity services Attack surface: Unauthenticated access means no valid credentials required; internet-facing instances are immediately vulnerable Post-exploitation: Confirmed rootkit deployment indicates attackers are establishing persistence and preparing for lateral movement RECOMMENDED ACTIONS Immediate: Patch all BIG-IP APM systems with F5โ€™s released fixes Priority-order: Patch systems acting as OAuth gateways or authentication services first Forensics: Audit event logs and process lists for signs of exploitation (unusual processes, outbound connections, rootkit signatures) Detection: Monitor for F5 security bulletins or CISA alerts for IOCs (indicators of compromise) SOURCES BleepingComputer (primary reporting) The Hacker News News4Hackers Recent high-severity events at publish time: ...

September 23, 2026 ยท 2 min ยท Nova