< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 8 sources · 14 days · First seen · Last updated

F5 BIG-IP APM security vulnerabilities

Overview

Security researchers and vendors have identified multiple critical vulnerabilities affecting F5 BIG-IP Access Policy Manager (APM) devices.

Initial reports detailed a sophisticated Linux rootkit named ‘PoisonedRefresh’ targeting F5 BIG-IP APM. This malware exploits CVE-2025-53521, an unauthenticated remote code execution flaw, to hide a web shell directly in memory to evade file-based scans. The infection process involves modifying the Apache binary and SELinux configurations to ensure persistence.

Subsequent findings identified a separate critical zero-day vulnerability, CVE-2026-94127, also affecting F5 BIG-IP APM. This heap-based buffer overflow allows unauthenticated attackers to execute arbitrary code via specially crafted traffic sent to an affected OAuth configuration. This flaw has been added to CISA’s Known Exploited Vulnerabilities catalog, with remediation required for U.S. federal civilian agencies.

Entities

CISA · F5 · Sophos · Bifrost · ESET

Timeline

  1. [TECHNOLOGY] 7 sources
    Critical vulnerabilities discovered in Bifrost AI gateway and F5 BIG-IP

    Critical vulnerabilities have been discovered in the Bifrost AI gateway and F5 BIG-IP APM, both allowing unauthenticated remote code execution. F5's flaw is currently being exploited in the wild.

  2. [TECHNOLOGY] 3 sources
    F5 BIG-IP devices targeted by memory-resident Linux rootkit

    Hackers are using a Linux rootkit named ‘PoisonedRefresh’ to deploy memory-resident web shells on compromised F5 BIG-IP APM devices, evading standard file scans.

Sources

bitnewsbot.com · csoonline.com.au · cybernoz.com · expertinsights.com · networkworld.com · securityaffairs.com · socprime.com · theregister.com