F5 BIG-IP APM Flaw Reclassified as Critical RCE with Active Exploitation

F5 reclassified CVE-2025-53521 in BIG-IP Access Policy Manager (APM) from a denial-of-service vulnerability to unauthenticated remote code execution (RCE). BIG-IP APM is a centralized access management proxy that controls network and application access. The vulnerability allows attackers to execute code remotely on unpatched systems with access policies configured on virtual servers, without any authentication. Shadowserver found over 14,000 BIG-IP APM instances exposed online that remain vulnerable. F5 confirmed active exploitation and published indicators of compromise. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this CVE to its Known Exploited Vulnerabilities catalog and set a patch deadline that has now passed. Many operators likely deprioritized patching when the flaw was classified as DoS. The reclassification and active exploitation mean the risk is now critical. Teams must verify their BIG-IP APM versions and patch immediately or isolate vulnerable,

Part of the PlainSec briefing for 2026-04-26

Sources