Exposed F5 access servers face active remote takeover attempts

Exposed F5 access servers face active remote takeover attempts. Affected F5 access servers can be remotely compromised without authentication, and attackers are already exploiting the weakness.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 23rd, 2026.

Affected F5 access servers can be remotely compromised without authentication, and attackers are already exploiting the weakness. The exposure is configuration-specific. It affects BIG-I P APM virtual servers that have both an access policy and an OAuth authorization-server profile. F5 released engineering hotfixes after detecting the attacks, and CISA added the issue to its Known Exploited Vulnerabilities catalog.

A successful attack could give an intruder control over a system that handles application traffic and access decisions. Importantly, restricting only the management interface won’t block malicious traffic from reaching an affected virtual server because the vulnerable component sits in the traffic-processing path. For leaders, that makes an emergency change window appropriate when the exposed configuration is confirmed. For defenders, the immediate tasks are to inventory the configuration, patch it, and correlate OAuth authentication failures with suspicious commands and TMM crashes. The broader lesson is that knowing a product is installed isn’t enough. Exposure often depends on how it’s configured. Identify affected OAuth authorization-server configurations, install the applicable hotfix, and hunt for related activity immediately.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Exposed F5 access servers face active remote takeover attempts
Broadcast by