CVE Tools

CVE-2025-53521

BigIP APM Vulnerability

Exploited in the wild. In CISA KEV since 2026‑03‑27. A vendor fix is available.

Published Updated Sources: CVE.org, NVD

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check whether your F5 BIG-IP device has BIG-IP APM configured with an access policy on a virtual server.
  2. Determine your current BIG-IP version from the device’s system information screen or your vendor management tooling.
  3. Upgrade to one of the fixed versions: 17.5.1.3, 17.1.3, 16.1.6.1, or 15.1.10.8 (covers BIG-IP and the listed BIG-IP module names).
  4. If you cannot patch immediately, follow F5’s mitigations from the vendor remediation article linked in the advisory and restrict/limit exposure of the affected virtual server endpoints as directed by F5.
  5. After updating, review BIG-IP logs and system indicators for signs of compromise, and confirm the device continues to enforce the expected access-policy configuration.

What it is

From the CVE record

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

In plain language

Written by AI from the record

CVE-2025-53521 is a weakness in F5 BIG-IP that can let an attacker run code remotely without logging in, and it can also knock the system offline—if you use BIG-IP APM with an access policy on a virtual server, you should act now.

CVE-2025-53521 is an unauthenticated remote code execution in F5 BIG-IP (APM access policy configured on a virtual server), where crafted network traffic triggers code execution that can lead to denial of service; it is listed in CISA KEV and has been exploited in the wild.

If you're affected

  • Full device compromise
  • Service outage / denial of service
  • Malware persistence on servers
  • Customer login/session disruption

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS83rd
CISA KEV
CISA KEV

Listed as exploited in the wild since 2026-03-27.

US federal agencies must remediate by 2026-03-30.

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

2.3% chance of exploitation activity in the next 30 days, which ranks it in the 83rd percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Attention now

Sustained, driven by in-the-wild reports.

Lifecycle

9 events over 253 days, from the signal feeds we watch.

  1. OpenVAS check added
  2. EPSS band changemoderate → low
  3. EPSS band changelow → moderate
  4. Added to CISA KEV
  5. Patch availablerecord updated
  6. Publishedweakness classified, att&ck mapped

Affected products

Technical detail

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Scored 7.5 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality NoneNo confidentiality impact
  • Integrity NoneNo integrity impact
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for BIG-IP, not every advisory. This one: actively exploited.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store