F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

2026-09-23T07:23:21Z•1b9d7a161d2f13ff58ffcdb84d87cc0d79aa4e145d15d6894d7d505a54cb4c30
CVE-2026-86296AI malwareCISACheck PointD-LinkF5 BIG-IPLinux kernelMFA bypassMicrosoft DefenderOracle PeopleSoftWordPressZyxelactive exploitationcredential theftdata breachnetwork appliancesphishing-as-a-serviceremote code executionsupply chain compromisezero-day

What happened

A BleepingComputer security-news digest reports widespread active exploitation and zero-day activity affecting F5 BIG-IP APM, Check Point Security Management Server, D-Link DIR-822A routers, Zyxel GS1900 switches, Linux kernels, WordPress, Microsoft Defender, and potentially Oracle PeopleSoft. It also covers credential theft through rogue MFA providers, phishing-as-a-service compromising Microsoft accounts, AI-enabled malware, data breaches, and supply-chain abuse. Organizations should prioritize patching or mitigating actively exploited edge, network, security-management, and endpoint systems

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
1b9d7a161d2f13ff58ffcdb84d87cc0d79aa4e145d15d6894d7d505a54cb4c30
Enrichment time
2026-09-23T07:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.