Back to all news
Cybersecurity 2 min read

F5 Issues Critical Patch for BIG‑IP APM Zero‑Day Exploited in Remote Code Attacks

F5 releases emergency updates to close a vulnerability that allows unauthenticated attackers to execute code on BIG‑IP APM appliances

F5 Networks has issued security updates to fix a critical BIG‑IP APM zero‑day flaw that is being actively exploited for remote code execution. Fiji businesses using F5 appliances must apply the patches immediately to avoid compromise.

What happened

F5 Networks has released security updates to address a critical BIG‑IP Access Policy Manager (APM) zero‑day vulnerability that is being exploited in remote code execution (RCE) attacks. The flaw allows unauthenticated attackers to execute arbitrary code on affected BIG‑IP APM devices.

Why it matters

The vulnerability is classified as critical because it can be leveraged without credentials, giving attackers full control of the appliance and any network traffic it proxies. Exploitation of the flaw has already been observed in the wild, meaning threat actors are actively targeting unpatched BIG‑IP APM installations. A successful breach can expose sensitive data, disrupt services, and provide a foothold for further lateral movement within an organization’s network.

What this means for Fiji businesses

For Fiji organisations that rely on F5 BIG‑IP APM for secure remote access, VPN termination, or web‑application delivery, the exposure is immediate:

  • Any unpatched appliance is vulnerable to unauthenticated RCE, regardless of the size of the deployment.
  • The Pacific region’s limited cybersecurity staffing makes rapid patching essential to avoid a breach that could affect customer data and service continuity.
  • Companies in sectors such as finance, tourism, and government that handle personal or regulated data are especially at risk because a compromised APM could expose that data to attackers.

What businesses should do now

  1. Identify all F5 BIG‑IP APM devices in your environment. Use inventory tools or consult your network team to confirm version numbers.
  2. Apply the latest F5 security updates immediately. The patches are available on the F5 support portal and address the zero‑day flaw.
  3. Validate the patch by testing in a staging environment where possible, then roll out to production during a maintenance window.
  4. Review firewall and intrusion‑detection rules to ensure they block unexpected traffic to the APM management interfaces.
  5. Monitor logs for any anomalous activity, especially attempts to access OAuth endpoints or other authentication services that the APM proxies.
  6. Update incident‑response playbooks to include steps for a potential APM compromise, ensuring rapid containment if exploitation is detected.
  7. Engage with your service provider if you use a managed security service; confirm they have applied the patches on your behalf.

Taking these steps promptly will reduce the risk of a successful RCE attack on your BIG‑IP APM infrastructure and help maintain the integrity of your network services.

Independent evidence

Sources

3 sources

Aura Digital Fiji · Digital services

Need help applying this technology to your business?

Custom websites, ecommerce, business email, security, mobile apps and IT systems built for Fiji businesses.

Continue reading

Related intelligence

All news →