# F5 patches exploited BIG-IP APM flaw as U.S. agencies face Friday deadline

_Published Wednesday, September 23, 2026 at 5:08 AM EDT · Security, Infrastructure · Latest · Tier 1 — Major_

![F5 patches exploited BIG-IP APM flaw as U.S. agencies face Friday deadline — Primary](https://www.bleepstatic.com/content/hl-images/2026/06/18/F5.jpg)

F5 has released security updates for a critical BIG-IP APM flaw that it says attackers have exploited to run code remotely. BIG-IP APM manages access to organizational networks and applications. The vulnerability affects configurations that use an APM access policy and an OAuth profile on a virtual server; deployments used strictly as OAuth clients or resource servers without authorization server profiles are unaffected.

The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its list of known exploited vulnerabilities on Tuesday and ordered federal agencies to secure their networks by Friday. F5 also provided a mitigation through its support service for administrators who cannot immediately install the updates.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/)

---
Canonical: https://techandbusiness.org/newswire/WcB8M-DLIV4EwzxJ8eJOPR
Published: 2026-09-23T09:08:02.225Z
Story chronology: 2026-09-23T07:17:23.000Z
Retrieved: 2026-09-23T10:30:41.542Z
Publisher: Tech & Business (techandbusiness.org)
