Skip to main content

Share story

Security

Over 14,000 F5 BIG-IP APM Instances Remain Exposed to Active Remote Code Execution Attacks

Over 14,000 F5 BIG-IP APM Instances Remain Exposed to Active Remote Code Execution Attacks Image: Primary
Internet security watchdog Shadowserver has identified more than 14,000 F5 BIG-IP Access Policy Manager instances exposed online that remain vulnerable to a critical remote code execution vulnerability, even as attacks exploiting the flaw are actively ongoing, according to BleepingComputer. The vulnerability, rated critical severity, allows an unauthenticated attacker to execute arbitrary code on affected BIG-IP systems. BIG-IP is widely deployed by enterprises, government agencies, and telecommunications providers as an application delivery controller and load balancer, making the exposure particularly significant from a blast-radius perspective. F5 released patches for the vulnerability and issued a security advisory urging customers to update affected systems. Despite the availability of fixes and public disclosure of active exploitation, Shadowserver's internet-wide scanning found a substantial number of instances remain unpatched and directly reachable from the internet. The gap between patch availability and actual patch deployment is a persistent problem in enterprise security. BIG-IP devices often sit at the network perimeter handling critical traffic flows, and operators may delay patching due to concerns about service interruption or the complexity of change management processes in large organizations. F5 BIG-IP has been targeted in previous high-profile exploitation campaigns. In 2020 and 2021, threat actors including nation-state groups and ransomware operators exploited earlier BIG-IP vulnerabilities to gain initial network access at government and financial sector targets. Organizations running BIG-IP APM are advised to apply the available patches immediately, restrict management interface access to trusted IP ranges, and review logs for signs of exploitation activity predating the patch.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Infrastructure Products
Infrastructure Products

Amazon commits more than $1 billion to data center communities

Amazon committed Friday to donating more than $1 billion over five years to communities neighboring its data centers, Ars Technica reported. AWS chief executive Matt Garman said communities would choose priorities including educat...

Robotics Capital
Robotics Capital

Fortem raises $50 million with Lockheed Martin participating

Counter-drone company Fortem has raised $50 million in Series B funding, with Lockheed Martin participating, Bloomberg reported. Fortem is seeking to expand manufacturing and bookings rapidly. CEO Jon Gruen said its relationship w...

AI Infrastructure
AI Infrastructure

Broadcom syndicate seeks $60 billion for AI chip financing

Broadcom's Wall Street syndicate is starting to gather $60 billion in fresh AI chip financing, Bloomberg reported, citing sources. The financing effort would help Anthropic and other companies access chips and other infrastructure...

Products Infrastructure
Products Infrastructure

TXO acquires Wesbell Communications to expand infrastructure services

TXO announced Friday that it had acquired Wesbell Communications for an undisclosed sum, adding network and engineering services, managed services, asset recovery and third-party maintenance capabilities. Wesbell serves Tier 1 tel...

Products
Products

Google raises Pixel 10a starting price from $499 to $599

Google raised the Pixel 10a's US starting price Friday from $499 to $599, with the 256GB model now costing $699, 9to5Google reported. The new prices are in effect at the Google Store, Amazon and Best Buy. Google Store also lists ...