Vulnerabilities & Exploits

CISA Adds BIG‑IP APM RCE to Known Exploited Vulnerabilities

F5 reclassified the bug from DoS to unauthenticated remote code execution across multiple APM versions and published indicators of compromise confirming exploitation.

7 sources · Apr 3

CVE-2025-53521

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: when a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code… EPSS 2% (82nd percentile).

CISA federal remediation date Mar 30 · date passed

Timeline

Sources

Vendor digest: F5

Part of the PlainSec briefing for 2026-03-29

Every edition of this story: CISA Adds BIG‑IP APM RCE to Known Exploited Vulnerabilities

More from today