CISA Adds BIG‑IP APM RCE to Known Exploited Vulnerabilities
F5 reclassified the bug from DoS to unauthenticated remote code execution across multiple APM versions and published indicators of compromise confirming exploitation.
CVSS 9.8 CRITICAL: when a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code… EPSS 2% (82nd percentile).
CISA federal remediation date Mar 30 · date passed
F5 BIG-IP Vulnerability Reclassified as RCE, Under Exploitation
CVE-2025-53521 was first disclosed in October as a high-severity denial-of-service (DoS) flaw, but new information reveals the bug is much more dangerous.
5-month-old F5 BIG-IP DoS bug becomes critical RCE exploited in the wild
Reclassified as a remote code execution flaw, the F5 BIG-IP APM vulnerability has been upgraded to CVSS 9.8, requiring immediate patching and compromise assessment.