ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardBriefings › F5 BIG-IP APM under active attack via critical 0-day RCE — patch is out
IT SECURITY DESK

F5 BIG-IP APM under active attack via critical 0-day RCE — patch is out

Three products were reported under active exploitation, F5's access-management module the most serious, and Google shipped a Chrome update closing six flaws.

The Register reported that attackers are exploiting a critical zero-day remote code execution flaw in F5 BIG-IP APM, and that both CISA and F5 warn it is under active exploitation. The Register also reported that a patch is available. Prioritise this one: BIG-IP APM sits at the network edge as an access proxy, and a remotely exploitable RCE there is a route into everything behind it. Match your estate against F5's advisory and apply the vendor's fix.

Two more products were reported under active exploitation. BleepingComputer reported that Check Point has confirmed active exploitation of a pre-authentication remote code execution vulnerability in the VPN certificate-handling functionality of its Security Gateway product. BleepingComputer separately reported that threat actors have moved from probing WordPress sites affected by a critical flaw to exploiting it, writing files to disk that execute shell commands when accessed. Check your Check Point Security Gateway and WordPress installs against each vendor's advisory and patch.

Google shipped a Chrome stable channel update fixing six flaws. Google's advisory record lists CVE-2026-93374, CVE-2026-93373 and CVE-2026-93372, each carrying a CVSS base score of 9.6 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), and CVE-2026-93382, CVE-2026-93381 and CVE-2026-93377, each scored 8.8 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Google lists Chrome up to the fix in 153.0.8010.52 as affected. Update to 153.0.8010.52 and confirm your fleet has restarted to apply it (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html).

On the supply-chain and social-engineering front: The Hacker News reported, citing Aikido, Go-based malware distributed via two Go Modules and two Terraform providers — the first time threat actors have used HashiCorp's centralised registry as a distribution vector. The Hacker News also reported that the private email address GitLab gives users for filing issues by email is a credential: anyone who obtains it can email a patch that GitLab commits in the victim's name to any branch they can push to, including main, and can start CI/CD jobs that run as them. BleepingComputer reported that the "third-party.com" placeholder domain now serves a fake Cloudflare verification page that tries to trick Windows users into running PowerShell commands (a ClickFix attack), and separately that a new Android malware-as-a-service platform called RemControl is targeting users in Europe and Canada through malvertising impersonating the TVTap IPTV app. Treat that GitLab issue-by-email address as a secret, and review your Terraform provider and Go module sources against Aikido's findings.

For asset owners, CISA and the FBI published a joint fact sheet on considerations for critical-infrastructure operators working with third-party ICS integrators.

Related