Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth pr...
A critical unauthenticated remote code execution vulnerability, tracked as CVE-2025-53521, in F5's BIG-IP Access Policy Manager (APM) systems is currently being exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities...
A sophisticated Linux implant targeting F5 BIG-IP Access Policy Management (APM) environments has been identified, exploiting CVE-2025-53521, an unauthenticated remote code execution vulnerability. This malware, referred to as 'PoisonedRefresh,' employs advanced techniques like function hooking and...