CISA added CVE-2025-53521 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of a flaw in F5 BIG-IP Access Policy Manager (APM). The vulnerability affects BIG-IP 17.x, 16.x, and 15.x when an APM access policy is configured on a virtual server, and specially crafted unauthenticated traffic can crash and restart the TMM process, creating a path to potential root-level remote code execution. F5 had initially treated the issue as a denial-of-service bug, but reclassified it as RCE after new information emerged, sharply raising the severity of the threat.
F5 said fixes were released in February 2025, with patched versions including 17.1.0.4, 16.1.4.3, and 15.1.10.2 or later, and warned that end-of-technical-support systems should be considered unprotected. CISA ordered Federal Civilian Executive Branch agencies covered by BOD 22-01 to remediate by March 30, 2026, while urging organizations to assess internet-exposed F5 devices, review F5-published indicators of compromise and attacker tradecraft, and investigate for signs of intrusion. Reporting also noted the KEV listing comes after F5's earlier nation-state compromise, which allegedly exposed source code and undisclosed vulnerability information.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
As of 2026-03-31, Shadowserver telemetry showed more than 17,100 F5 BIG-IP APM instances exposed globally, with over 14,000 still publicly reachable. The United States and Japan had the highest concentrations of exposed systems amid ongoing exploitation of CVE-2025-53521.
On 2026-03-31, CERT-FR published an alert on CVE-2025-53521 affecting F5 BIG-IP APM after F5 reported active exploitation. The advisory recommended compromise assessments using F5's indicators, including suspicious files, modified binaries, audit log evidence of iControl REST abuse, SELinux tampering, and bash command execution on affected systems.
Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies were required to patch or apply approved mitigations for CVE-2025-53521 by March 30, 2026. The deadline followed CISA's KEV listing of the actively exploited flaw.
On March 28, 2026, CISA added CVE-2025-53521 affecting F5 BIG-IP APM to its Known Exploited Vulnerabilities catalog after confirming exploitation in the wild. CISA also urged organizations to assess exposure and inspect internet-accessible F5 devices for signs of compromise.
In March 2026, F5 confirmed that CVE-2025-53521 was being actively exploited in vulnerable BIG-IP versions. The company published indicators of compromise, attacker tradecraft, and affected and fixed version details.
Based on new information obtained in March 2026, F5 updated its assessment of CVE-2025-53521 from a denial-of-service issue to a remote code execution vulnerability. This significantly raised the severity and potential impact of the flaw.
In August 2025, attackers reportedly breached F5 and stole source code and information on undisclosed vulnerabilities. Reporting linked this compromise to later concern that threat actors may have gained advance insight into exploitable flaws.
F5 released patched BIG-IP versions for CVE-2025-53521 in February 2025, including 17.1.0.4, 16.1.4.3, and 15.1.10.2 or later. The flaw affected BIG-IP 17.x, 16.x, and 15.x when an APM access policy was configured on a virtual server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
13 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecybersecuritynews.com
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcethehackernews.com
Open sourcethecyberthrone.in
Open sourcecvereports.com
Open sourcefacebook.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.