CRITICALVulnerability
Global

Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks

Thursday, April 2, 2026 at 08:25 AM UTC·Source: BleepingComputer

Updated: Thursday, April 2, 2026 at 04:49 PM UTC

Executive Summary

Internet security watchdog Shadowserver has found over 14,000 BIG-IP APM instances exposed online amid ongoing attacks exploiting a critical-severity remote code execution (RCE) vulnerability. [...]

Analysis

Internet security watchdog Shadowserver has found over 14,000 BIG-IP APM instances exposed online amid ongoing attacks exploiting a critical-severity remote code execution (RCE) vulnerability. [...]
Source Attribution

Originally published by BleepingComputer on Apr 2, 2026.

Related Threats