14,000+ F5 BIG-IP APM devices still exposed as active CVE-2025-53521 RCE attacks continue


A critical flaw in F5 BIG-IP Access Policy Manager is under active exploitation, and thousands of internet-facing systems still appear exposed. CVE-2025-53521 now carries a critical severity rating after F5 changed its description from a denial-of-service issue to remote code execution, while CISA has already added it to the Known Exploited Vulnerabilities catalog.

The immediate concern is scale. Shadowserver said it fingerprinted more than 17,100 exposed F5 BIG-IP APM instances worldwide on March 31, 2026, describing the count as a population assessment rather than a confirmed list of still-vulnerable devices. Reports citing that data say more than 14,000 systems remained exposed online after some organizations started patching.

This matters because BIG-IP APM often sits at the edge of enterprise networks and controls remote access to internal applications. If attackers gain remote code execution on one of these appliances, they can potentially use it as a path into more sensitive systems.

Why this F5 flaw became much more urgent

Part of the problem came from the flawโ€™s history. F5 originally disclosed CVE-2025-53521 in October 2025 as an issue that could make TMM terminate, which framed it as a denial-of-service problem. On March 27, 2026, NVDโ€™s change history shows F5 updated the CVE description to say that specific malicious traffic can lead to remote code execution.

That change reshaped the response timeline. CISA added the bug to KEV on March 27, 2026 and set a March 30, 2026 remediation deadline for federal civilian agencies, with guidance to apply vendor mitigations or discontinue use if mitigations were unavailable.

F5โ€™s advisory also says the original remediation already fixes the recategorized RCE in the patched versions. In other words, organizations that applied the earlier fix were already protected, but teams that delayed because they saw it as a lower-priority DoS issue may now face a much higher-risk situation.

What versions are affected and what admins should do now

NVD lists the flaw as critical, with F5 CNA scores of 9.3 in CVSS v4.0 and 9.8 in CVSS v3.1. The public description says the issue affects BIG-IP APM when an access policy is configured on a virtual server.

Public F5 release notes and related vendor references point to patched branches including 15.1.10.8, 16.1.6.1, 17.1.3, 17.5.1.3, and 21.0.0, depending on the supported train in use. Older versions that reached end of technical support were not evaluated, which means some legacy deployments may remain especially risky.

F5 has also published indicators of compromise tied to related malicious activity, and third-party reporting says attackers have used the bug to deploy web shells. For defenders, that means patching alone may not be enough. Teams should patch, then review logs, check exposed assets, and hunt for signs of post-exploitation.

CVE-2025-53521 at a glance

ItemDetails
CVECVE-2025-53521
ProductF5 BIG-IP Access Policy Manager (APM)
Current impactRemote code execution
Exploitation statusActively exploited
CISA KEV addedMarch 27, 2026
Federal due dateMarch 30, 2026
SeverityCritical
Key exposure data point17,100+ internet-exposed APM instances seen on March 31, 2026
Main riskAttackers can compromise edge infrastructure and pivot deeper into internal networks

What security teams should prioritize

  • Patch every exposed BIG-IP APM instance on a supported branch immediately.
  • Treat internet-facing APM appliances as potentially compromised if they remained exposed after public exploitation began.
  • Review F5โ€™s IoC guidance and inspect systems for suspicious files, web shells, or abnormal access behavior.
  • Inventory all external access gateways and verify that no forgotten or secondary APM interface remains online.
  • Flag unsupported BIG-IP versions for urgent replacement or isolation because F5 did not evaluate end-of-support releases.

FAQ

What is CVE-2025-53521?

It is a critical vulnerability in F5 BIG-IP APM. F5 now describes it as an issue where specific malicious traffic can lead to remote code execution when an APM access policy is configured on a virtual server.

Is this bug being exploited in the wild?

Yes. CISA added it to the Known Exploited Vulnerabilities catalog on March 27, 2026, which signals evidence of active exploitation.

Why are people saying the risk increased recently?

Because the flaw was first presented as a denial-of-service issue, then later recategorized as remote code execution. That changed how defenders and attackers viewed its impact.

How many F5 APM devices are exposed online?

Shadowserver said it saw more than 17,100 exposed instances on March 31, 2026. Some reports based on that dataset said more than 14,000 systems still appeared exposed after partial patching.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages