$ techbeacon▋
CVE & Exploits

F5 BIG‑IP APM Critical Flaw Enables Unauthenticated Remote Code Execution

F5 BIG‑IP APM Critical Flaw Enables Unauthenticated Remote Code Execution

F5 Networks has confirmed a critical remote‑code‑execution vulnerability in its BIG‑IP Access Policy Manager (APM) that is already being leveraged by attackers in the wild.

The flaw, cataloged as CVE‑2026‑94127, allows an unauthenticated adversary to run arbitrary code on any BIG‑IP system that exposes the APM interface to the internet, potentially granting full control of the underlying server.

BIG‑IP APM is a widely deployed component used by enterprises, service providers, and government agencies to enforce authentication, single‑sign‑on and traffic‑filtering policies across web applications and VPN connections. Because the module often sits at the perimeter of networks, a compromise can open a direct path to internal resources.

The vulnerability was initially reported by the security research collective GBHackers, prompting F5 to issue an emergency advisory and release patches within days of disclosure. In its advisory, F5 warned that the vulnerability is being actively exploited, citing evidence of intrusion attempts observed on several customer environments.

Administrators are urged to apply the supplied patches immediately, restrict access to the APM management ports, and enable additional monitoring for suspicious activity such as unexpected outbound connections or anomalous process launches. For systems that cannot be patched quickly, F5 recommends disabling the vulnerable services or placing them behind additional firewalls.

Industry analysts note that the incident underscores the broader risk posed by high‑profile network appliances that are frequently internet‑facing. As threat actors continue to hunt for unpatched infrastructure, the BIG‑IP APM flaw serves as a reminder that timely vulnerability management remains a cornerstone of cyber‑defense strategies.

Source: GBHackers
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related