Researchers observe hackers remotely exploiting a critical bug in BIG-IP products from F5 that act as load balancers within enterprise networks; patch available
F5 released a patch … Lindsey O'Donnell / Threatpost : Admins Urged to Patch Critical F5 Flaw Under Active Attack Robert Lemos / Dark Reading : Attackers Scan for Vulnerable BIG-IP Devices After Flaw Disclosure NCC Group Research : RIFT: F5 Networks K52145254: TMUI RCE vulnerability CVE-2020-5902 Intelligence Tweets: Catalin Cimpanu / @campuscodi : Initial attacks attempted to extract admin passwords and device settings. See here: https://www.zdnet.com/... Since Saturday, we've also seen some gangs try to infect systems with cryptomining malware, but also a few attackers trying to install webshells for future access https://twitter.com/... @wired : Any company that uses BIG-IP products sold by F5 Networks had a rude interruption to their weekend, as a critical vulnerability turned July 4 into a race to implement a fix. Those who haven't done so yet may now have a much larger problem on their hands. https://www.wired.com/... Andy Greenberg / @a_greenberg : Big thank you to all the networking folks who spent their July 4 weekend patching this very bad bug—and my sympathy to those who didn't. https://www.wired.com/...
Context & Ripple Effects
This is the disclosure-to-exploitation cycle at its fastest: researchers watch attacks against F5's BIG-IP load balancers begin almost immediately after the CVE-2020-5902 details land, with a patch available and defenders racing scanners to internet-facing devices. The early attack payloads — admin credential theft, device-settings extraction, then cryptominers and webshells — show adversaries treating the flaw less as an end goal than a foothold into enterprise interiors.
The arc around this event runs both directions. Two months later, CISA attributed exploitation of F5, Citrix, Pulse Secure, and Exchange bugs to hacking groups tied to China's Ministry of State Security (CISA linked state-backed groups exploiting the same F5 bugs), confirming the target profile. And the pattern repeats: F5 patched another actively exploited BIG-IP critical in 2022 (another actively exploited BIG-IP flaw two years later), while Fortinet's experience shows how badly remediation lags even after patches ship (most Fortinet SSL VPN interfaces stayed unpatched weeks after a fix).
First-order effects
- Admins running internet-facing BIG-IP devices face immediate exposure: attackers are remotely executing code via the TMUI interface, harvesting admin passwords and device settings that unlock broader network access, so patching becomes an emergency rather than routine maintenance.
Second-order effects
- Because BIG-IP sits at the traffic-control layer of enterprise networks, stolen admin credentials and webshells on these devices give attackers durable pivots into internal systems — turning one vendor's RCE into multi-vendor breach risk across every customer behind the box.
Third-order effects
- Edge appliances — load balancers, VPN gateways, firewalls — keep proving to be the softest perimeter entry point (the same dynamic later hit VMware under a CISA patch-or-remove order and Fortinet repeatedly), pointing toward regulator-mandated patching SLAs and procurement standards for network infrastructure vendors.
The trend: Enterprise network-edge appliances are displacing endpoints as the primary initial-access target, with disclosure-to-exploitation windows compressing faster than fleet-wide patching can respond.