F5 announced seven new vulnerabilities in their BIG-IP and BIG-IQ products, including 4 critical CVEs about remote code execution (RCE).
Successful exploitation of the critical vulnerabilities would likely lead to a full system compromise. Attackers would reportedly be able to intercept application traffic from the controller and move laterally to the victims’ internal network. System administrators are strongly recommended to apply the fixes as soon as possible.