Attackers Exploit RCE Flaw as 14,000 F5 BIG-IP APM Instances Remain Exposed

robot
Abstract generation in progress

Attackers are actively exploiting a critical Remote Code Execution (RCE) flaw, CVE-2025-53521, in F5 BIG-IP APM instances, leaving over 14,000 vulnerable systems exposed online. The vulnerability, which was reclassified from a Denial-of-Service (DoS) issue in March 2026, has a CVSS score of 9.8 and allows RCE through specially crafted malicious traffic when an access policy is enabled. The U.S. CISA had already added this flaw to its Known Exploited Vulnerabilities catalog, ordering federal agencies to fix it by March 30, 2026.

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin