Exploit
Critical F5 BIG-IP APM vulnerability (CVSS 9.8) actively exploited
Key Facts
Signal Type
Exploit
Industry
Cybersecurity
Companies
F5 Networks
Date
September 22, 2026
F5 Networks disclosed a severe vulnerability (CVSS 9.8) in BIG-IP Access Policy Manager (APM). The flaw allows unauthenticated remote attackers to send crafted network traffic and achieve full device takeover via remote code execution. Active exploitation has been confirmed, with F5 providing indicators of compromise (IoCs) from successful attacks. The NCSC Netherlands has released an advisory urging immediate patching.
Any organization using F5 BIG-IP APM, especially those with internet-facing deployments. The advisory from the NCSC Netherlands specifically targets Dutch entities, but the vulnerability affects all global installations. Customers who have not yet applied the security update or workarounds are at immediate risk of compromise.
Monitor for additional IoCs or proof-of-concept code emerging as exploitation escalates. F5 may issue supplementary advisories for related products. Expect increased regulatory scrutiny in the Netherlands and potential enforcement actions against unpatched systems. Security teams should reassess network segmentation and access controls in the wake of this compromise.
Source:
NCSC Netherlands NewsGet cybersecurity signals in your CRM
Data breaches, ransomware events, funding rounds, and M&A across security vendors and targets.
