Active Exploitation of Critical RCE Vulnerability in F5 BIG-IP APM
A critical unauthenticated remote code execution vulnerability in F5 BIG-IP Access Policy Manager is currently being exploited in the wild, allowing attackers to gain full system control.
A critical, unauthenticated remote code execution (RCE) vulnerability has been identified in F5 Networks BIG-IP Access Policy Manager (APM), an enterprise network and application access control solution. With a CVSS score of 9.8, this flaw allows unauthenticated attackers to send specially crafted network traffic to the device, enabling the execution of arbitrary code and leading to full system compromise. The Dutch National Cyber Security Centre (NCSC-NL) has confirmed that this vulnerability is being actively exploited by threat actors. Given the nature of the device as a network perimeter component, successful exploitation allows attackers to gain persistent access, exfiltrate sensitive data, or pivot into internal networks. Organizations utilizing F5 BIG-IP APM must prioritize the installation of security updates provided by F5 Networks and conduct forensic checks for signs of compromise using the indicators provided in the vendor's advisory.
Attack Chain
- Attacker performs network reconnaissance to identify internet-facing F5 BIG-IP APM instances.
- Attacker crafts malicious network packets designed to exploit the vulnerability within the APM module.
- Attacker sends the malicious traffic to the target APM device without requiring prior authentication.
- The vulnerable APM service processes the crafted traffic, resulting in memory corruption or logic exploitation.
- Arbitrary code is executed on the underlying BIG-IP system with the privileges of the APM service.
- Attacker establishes persistence or deploys additional malicious payloads to maintain access.
- Attacker utilizes the compromised device for lateral movement or data exfiltration from the internal network.
Impact
Successful exploitation results in full system compromise of the F5 BIG-IP APM appliance. This provides attackers with a foothold in the organization's network perimeter, allowing for the potential theft of credentials, interception of session traffic, and lateral movement into protected internal segments. The active exploitation status indicates a high risk of immediate compromise for any unpatched, internet-exposed systems.
Recommendation
Prioritized, concrete actions for detection engineering and security teams:
- Immediately identify all internet-facing F5 BIG-IP APM instances and verify their patch status against the latest F5 security advisory.
- Apply the security updates provided by F5 Networks to address the vulnerability as a matter of urgency.
- Review network logs and system logs for unexpected traffic patterns or indicators of compromise (IOCs) explicitly referenced in the official F5 Networks security advisory.
- If immediate patching is not possible, implement the compensatory controls detailed in the F5 Networks security advisory to mitigate the risk of unauthenticated remote exploitation.
Immediate actions
Inventory and patch all F5 BIG-IP APM instances per vendor guidance.
Threat Hunt
Identify unauthorized network traffic directed at BIG-IP APM interfaces.
Data: Firewall and APM access logs
Mitigations
Apply vendor-supplied security updates or alternative compensatory controls.
Unauthenticated RCE in BIG-IP APM