การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Vulnerability

Critical Zero-Day RCE Vulnerability Discovered in F5 BIG-IP APM

FORTSECURE GLOBAL· 2026-09-24🛰 The Register - Security
#Vulnerability#Network Security#Incident Response#F5
Critical Zero-Day RCE Vulnerability Discovered in F5 BIG-IP APM

A severe zero-day Remote Code Execution vulnerability in F5 BIG-IP APM is currently being exploited in the wild, necessitating immediate patching by all system administrators.

Active Exploitation of F5 Systems

Security researchers and CISA have confirmed that a critical Remote Code Execution (RCE) zero-day vulnerability in F5 BIG-IP Access Policy Manager (APM) is currently being targeted by malicious actors. This flaw allows attackers to bypass authentication and execute arbitrary code, potentially leading to a full system compromise. Because these devices often sit at the edge of the corporate network, the impact of a successful exploit is high, potentially granting attackers lateral movement capabilities.

Remediation and Mitigation Steps

Immediate action is required for all organizations utilizing F5 BIG-IP appliances. Administrators must prioritize the application of the official security patch provided by F5. If an immediate patch is not possible, it is recommended to restrict management interfaces from public access and implement strict IP whitelisting to limit the attack surface. Furthermore, conducting a thorough audit of system logs for signs of suspicious activity or unauthorized access attempts is vital to ensure that the environment has not already been compromised prior to patching.


แหล่งที่มา: The Register - Security เผยแพร่ครั้งแรก: Wed, 23 Sep 2026 20:09:28 +0200 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: The Register - Security

เผยแพร่ครั้งแรก: Wed, 23 Sep 2026 20:09:28 +0200

บทความต้นฉบับ: https://www.theregister.com/security/2026/09/23/someones-attacking-a-critical-0-day-rce-in-f5-big-ip-apm/5298659

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog