F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

A critical zero-day vulnerability in F5’s BIG-IP Application Delivery Controller (ADC) has been exploited for unauthenticated remote code execution on OAuth servers, leaving organizations vulnerable to potential attacks. The vulnerability, which affects versions 14.x and 15.x of the BIG-IP APM module, allows an attacker to execute arbitrary code with root privileges on affected systems.

F5 Networks, a leading provider of application delivery and security solutions, has released patches to address the issue, but many organizations may not be aware that they are vulnerable. The vulnerability is particularly concerning because it can be exploited without authentication, making it potentially easier for attackers to gain access to sensitive systems. BIG-IP APM is widely used in cloud and on-premises environments, which means that a significant number of organizations are at risk.

The vulnerability works by exploiting a weakness in the way BIG-IP APM handles OAuth requests. When an attacker sends a specially crafted request to the affected system, it can bypass authentication mechanisms and execute arbitrary code with root privileges. This allows an attacker to gain complete control over the system, potentially leading to data breaches, system compromise, or other malicious activities.

The impact of this vulnerability is significant because BIG-IP APM is used in many critical infrastructure environments, including cloud services, financial institutions, and government agencies. The fact that it can be exploited without authentication means that even organizations with robust security measures in place may still be vulnerable. F5 Networks has stated that the issue is not related to any other vulnerabilities or exploits that have been previously disclosed.

To mitigate this risk, F5 recommends that customers apply the latest patches as soon as possible. This includes updating BIG-IP APM modules to version 14.1.2.3 or higher, which addresses the vulnerability. Organizations should also take steps to monitor their systems for suspicious activity and implement additional security measures, such as network segmentation and access controls, to prevent further exploitation.

In light of this critical vulnerability, it’s essential for organizations to prioritize patch management and ensure that all security patches are applied in a timely manner. This includes not only updating BIG-IP APM modules but also reviewing system configurations and implementing additional security measures to prevent similar attacks in the future.


Source: The Hacker News — 2026-09-23