When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Is CVE-2025-53521 exploited?
Listed in the CISA KEV catalog on 2026-03-27.
Federal remediation due 2026-03-30.
Past that date by 138 days.
EPSS puts exploitation in the next 30 days at 2%.
Public exploit code: none found in monitored sources.