F5 has patched a critical zero-day vulnerability in BIG-IP APM that is being actively exploited for remote code execution attacks. The flaw affects deployments using OAuth authorization server profiles, and CISA has ordered U.S. federal agencies to secure their systems by Friday. Cybercriminals and state-backed groups have a history of exploiting F5 vulnerabilities to breach networks and steal sensitive data.