< ciso
brief />
Tag Banner

All news with #f5 tag

28 articles

F5 patches critical BIG-IP APM zero‑day flaw

🔒 F5 released fixes for a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) that was actively exploited in the wild. The heap-based buffer overflow, tracked as CVE-2026-94127 and rated 9.8, affects deployments configured as OAuth authorization servers and can also impact appliance-mode systems when both APM and an OAuth authorization server profile are enabled. F5 published hotfixes for the 21.x, 17.5.x and 17.1.x branches and provided an iRule mitigation while patches are applied.
read more →

F5 BIG‑IP APM critical OAuth RCE patched

🛡️ F5 has disclosed and patched a critical heap‑based buffer overflow, CVE-2026-94127, in BIG‑IP Access Policy Manager when it is configured as an OAuth authorization server. The vulnerability allows unauthenticated remote code execution via specially crafted traffic to a virtual server hosting an APM access policy and an OAuth authorization server profile. F5 released engineering hotfixes for affected 21.1, 17.5 and 17.1 branches and provided an iRule mitigation for cases where immediate patching is not possible.
read more →

F5 warns of BIG‑IP APM RCE zero‑day being exploited

🔒 F5 released updates to fix a critical BIG‑IP APM zero‑day that is being actively exploited for remote code execution. The flaw affects deployments with APM configured as an access policy and OAuth profile on virtual servers; pure OAuth Client/Resource Server setups without authorization server profiles are not impacted. F5 urged admins to search for indicators like multiple OAuth failures and TMM SIGABRT events and provided an iRule mitigation for those unable to patch immediately.
read more →

Mass scanning of exposed Vite dev servers steals cloud secrets

🛡️ A large-scale campaign is scanning internet-exposed Vite development servers to extract AWS and Azure credentials by exploiting CVE-2026-39364 in affected Vite versions. F5 detected over 800 attacks and ~32,000 events, observing attackers append parameters like ?raw or ?import&raw to bypass file access controls and retrieve sensitive files. The operation targeted environment files, cloud credential/config files, Terraform and serverless state, and system files, using traversal and encoding tricks for evasion.
read more →

Stealth rootkit targets F5 BIG‑IP APM webtops

🔒 Sophos analyzed a Linux rootkit that hides web shells inside compromised F5 BIG‑IP APM environments by modifying PHP content in memory rather than writing files to disk. The implant hooks Apache’s PHP-loading process, targets specific BIG‑IP APM PHP files, and serves altered in‑memory versions so file‑integrity checks appear normal. It also provides a secondary access channel via a local UNIX socket, complicating detection and response.
read more →

F5 BIG-IP APM in-memory PHP web shell analysis

🛡️ Sophos on September 7 detailed malware targeting F5 BIG-IP Access Policy Manager that injects a PHP web shell into memory rather than writing it to disk. The malware hooks Apache and libphp, rewrites file-handling calls, and places a web shell in-memory when specific .php3 scripts are loaded, evading file-based detection. Related installer components modify /usr/sbin/httpd and other binaries and may persist through install images, with links to CVE-2025-53521 and mitigation guidance.
read more →

Critical nginx heap overflow allows remote crashes

🛡️ F5 released patches for a critical nginx heap buffer overflow (CVE-2026-42533) that can crash or restart worker processes and, in some environments, enable remote code execution. Fixed versions are nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1; systems on earlier releases should upgrade. The flaw occurs in the nginx script engine when a regex-based map's output variable is used in a string expression after an earlier regex capture, causing a two-pass evaluation mismatch that leads to overruns. F5 scores the flaw 9.2 (CVSS v4) and notes exposure depends on configuration rather than version alone.
read more →

F5 issues patches for two critical NGINX flaws

🛡️ F5 released updates to fix two critical vulnerabilities in NGINX Open Source that can allow remote code execution. CVE-2026-42530 is a use-after-free in the HTTP/3 QUIC module and CVE-2026-42055 is a heap-based buffer overflow affecting proxy and gRPC modules when specific directives are set. Patches are available across NGINX Open Source, NGINX Plus, Gateway Fabric, Instance Manager, WAF, DoS modules and Ingress Controller versions. Mitigations include disabling HTTP/3 for CVE-2026-42530 and adjusting ignore_invalid_headers or large_client_header_buffers settings for CVE-2026-42055.
read more →

F5 issues out‑of‑band patches for critical NGINX flaws

🔒 F5 released out-of-band updates to fix multiple NGINX vulnerabilities, including two critical flaws in the ngx_http_v3_module and ngx_http_proxy_v2/_grpc modules that can lead to DoS or code execution. The bugs cause use‑after‑free or heap buffer overflow in worker processes and affect NGINX Plus, Open Source, Gateway Fabric, and Instance Manager. Mitigations include disabling HTTP/3 and adjusting header buffer directives until patches are applied.
read more →

NGINX 18-Year Heap Overflow (CVE-2026-42945) Risks DoS/RCE

🔒 Researchers at DepthFirst AI found an 18-year-old heap buffer overflow in NGINX’s ngx_http_rewrite_module (CVE-2026-42945) that can cause denial of service and, under specific conditions, remote code execution. The flaw affects NGINX Open Source 0.6.27 through 1.30.0 and several F5-managed builds. Exploitation hinges on configurations using both rewrite and set directives and problems in the internal script engine’s two-pass handling of rewrites. Patches and mitigations are available, and F5 recommends replacing unnamed PCRE capture groups with named captures if immediate upgrades are not possible.
read more →

NGINX Rift: Critical 18-Year Rewrite Module Flaw Explained

⚠️ F5 and researcher depthfirst disclosed a critical heap buffer overflow in the ngx_http_rewrite_module affecting both NGINX Plus and NGINX Open Source. Tracked as CVE-2026-42945 (CVSS v4: 9.2) and dubbed NGINX Rift, the flaw can be triggered remotely via crafted URIs to cause DoS or, with ASLR disabled, lead to remote code execution. Fixes were released after responsible disclosure on April 21, 2026, across many NGINX releases and ecosystem products. Users should apply vendor updates or replace unnamed PCRE captures with named captures as a temporary mitigation.
read more →

14,000+ F5 BIG-IP APM Instances Exposed to RCE Attacks

⚠️ Shadowserver reports over 14,000 Internet-exposed BIG-IP APM instances remain vulnerable to CVE-2025-53521 after the flaw was reclassified from DoS to remote code execution. F5 confirmed the reclassification and warned that attackers are exploiting unpatched systems with access policies on virtual servers. F5 and CISA have published IOCs and mitigation guidance, and F5 recommends rebuilding compromised devices from known-good sources.
read more →

Critical RCE in F5 BIG-IP APM Originally Labeled DoS

⚠️ Five-month-old F5 BIG-IP APM flaw initially classified as a denial-of-service is now confirmed as a pre-authentication remote code execution vulnerability (CVE-2025-53521) being exploited in the wild. F5 updated its advisory, raised the CVSS to 9.8, and CISA added the issue to its KEV catalog after reports of active exploitation and observed root‑level malware persistence. Affected versions include 15.1.x, 16.1.x, 17.1.x and 17.5.x; F5 has released fixes, IOCs, and hardening guidance, but organizations should patch immediately and perform compromise assessments rather than rely solely on backups.
read more →

NCSC Urges Immediate Patching of Critical F5 BIG-IP Flaw

⚠️ The UK’s NCSC is urging organisations to immediately patch a critical vulnerability in F5 BIG-IP Access Policy Manager (APM) tracked as CVE-2025-53521, which is under active exploitation and can enable remote code execution when an APM access policy is configured on a virtual server. F5 has reclassified the issue from a denial‑of‑service to RCE with a revised CVSS of 9.8 after new information, and CISA has added it to its KEV catalog with a mandated federal patch deadline. Customers should follow F5’s incident‑handling and forensic guidance, isolate or rebuild affected systems, and report suspected compromises to the NCSC.
read more →

Critical F5 BIG-IP APM Flaw Reclassified as RCE; Patch Now

⚠️F5 Networks has reclassified a previously patched BIG-IP APM denial-of-service flaw (CVE-2025-53521) as a critical remote code execution vulnerability after evidence of active exploitation. Attackers are deploying webshells on unpatched devices that have access policies configured on virtual servers. F5 and CISA have published advisories and IOCs and are urging immediate patching, forensic checks of disks, logs, and terminal history, and adherence to incident-handling policies.
read more →

CISA Adds F5 BIG-IP CVE-2025-53521 to KEV After Exploitation

⚠️ CISA has added CVE-2025-53521 to its Known Exploited Vulnerabilities (KEV) list after evidence of active exploitation against F5 BIG-IP APM. The flaw, reclassified from a DoS to an RCE with a CVSS v4 score of 9.3, permits unauthenticated remote code execution when an APM access policy is configured on a virtual server. F5 published file, log, and traffic indicators and warned that webshells may run in memory. Organizations and FCEB agencies were directed to apply the vendor fixes by March 30, 2026.
read more →

CISA Adds F5 BIG-IP RCE to Known Exploited Vulnerabilities

⚠️ CISA has added CVE-2025-53521, a remote code execution vulnerability in F5 BIG-IP, to the Known Exploited Vulnerabilities (KEV) Catalog after evidence of active exploitation. The agency notes this class of flaw is a frequent attacker vector and poses significant risk to the federal enterprise. Under BOD 22-01, Federal Civilian Executive Branch agencies must remediate KEV entries by assigned due dates. CISA strongly urges all organizations to prioritize timely remediation, apply vendor fixes or mitigations, and maintain active monitoring to reduce exposure.
read more →

Serious F5 Breach: Build System and BIG-IP Code Compromised

⚠️ F5 disclosed a major intrusion in which a sophisticated, likely nation-state threat actor maintained long-term access to its internal network. During the compromise the attackers gained control of the build and distribution environment for BIG-IP updates and exfiltrated proprietary source code, documentation of unpatched vulnerabilities, and customer configuration files. F5 warned this data could enable widespread supply-chain and targeted attacks against many sensitive networks.
read more →

Weekly Recap: F5 Breach, Linux Rootkits, and Trends

🔒 This weekly recap highlights long-lived, stealthy intrusions and emerging tactics that are reshaping defender priorities. Chief among them, F5 disclosed a year-long breach involving the BRICKSTORM malware and stolen BIG-IP source material, while researchers uncovered new Linux rootkits such as LinkPro and campaigns abusing blockchain smart contracts for malware delivery. The report urges inventorying edge devices, prioritizing patches, and improving detection, baselining, and intelligence sharing.
read more →

Over 266,978 F5 BIG-IP Instances Exposed to Remote Attacks

⚠️ Shadowserver Foundation reports 266,978 internet-exposed F5 BIG-IP instances after F5 disclosed a breach in which nation-state actors stole source code and information on undisclosed BIG-IP flaws. F5 issued patches addressing 44 vulnerabilities and urged immediate updates for BIG-IP, F5OS, BIG-IQ, and related products. CISA issued an emergency directive requiring federal agencies to patch or mitigate affected devices by set deadlines. Nearly half of the detected instances are in the United States, with most others across Europe and Asia.
read more →