VORANT. Threat Intelligence Sign in Get the full feed

F5 BIG-IP APM RCE Flaw Exploited in Wild

high vulnerability financial-servicesgovernment-national

F5 confirms active exploitation of CVE-2025-53521, a remote code execution flaw in BIG-IP APM affecting versions 15.x through 17.x.

CISA/MS-ISAC issued an advisory warning that F5 has confirmed in-the-wild exploitation of CVE-2025-53521, a remote code execution vulnerability in BIG-IP Access Policy Management (APM). The flaw can be triggered by specially crafted malicious traffic when an APM access policy is configured on a virtual server, potentially allowing attackers to install programs, manipulate data, or create accounts with full user rights depending on the privilege level of the compromised process.

BIG-IP APM is widely deployed by enterprises, financial institutions, and government agencies to manage authentication and remote access, making this a high-value target for attackers seeking initial access into sensitive environments. Affected versions span the 15.x, 16.x, and 17.x branches, with patched releases available (15.1.10.8, 16.1.6.1, 17.1.3, and 17.5.1.3). Given the confirmed active exploitation and the critical role BIG-IP APM plays in perimeter access control, organizations running affected versions should prioritize immediate patching and review exposure of APM-enabled virtual servers to the internet.

Mentioned in this report

Vulnerabilities CVE-2025-53521KEV

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-f5-products-could-allow-for-remote-code-execution_2026-026

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free