14,000+ F5 BIG-IP APM devices still exposed as active CVE-2025-53521 RCE attacks continue
A critical flaw in F5 BIG-IP Access Policy Manager is under active exploitation, and thousands of internet-facing systems still appear exposed. CVE-2025-53521 now carries a critical severity rating after F5 changed its description from a denial-of-service issue to remote code execution, while CISA has already added it to the Known Exploited Vulnerabilities catalog.
The immediate concern is scale. Shadowserver said it fingerprinted more than 17,100 exposed F5 BIG-IP APM instances worldwide on March 31, 2026, describing the count as a population assessment rather than a confirmed list of still-vulnerable devices. Reports citing that data say more than 14,000 systems remained exposed online after some organizations started patching.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
This matters because BIG-IP APM often sits at the edge of enterprise networks and controls remote access to internal applications. If attackers gain remote code execution on one of these appliances, they can potentially use it as a path into more sensitive systems.
Why this F5 flaw became much more urgent
Part of the problem came from the flawโs history. F5 originally disclosed CVE-2025-53521 in October 2025 as an issue that could make TMM terminate, which framed it as a denial-of-service problem. On March 27, 2026, NVDโs change history shows F5 updated the CVE description to say that specific malicious traffic can lead to remote code execution.
That change reshaped the response timeline. CISA added the bug to KEV on March 27, 2026 and set a March 30, 2026 remediation deadline for federal civilian agencies, with guidance to apply vendor mitigations or discontinue use if mitigations were unavailable.

F5โs advisory also says the original remediation already fixes the recategorized RCE in the patched versions. In other words, organizations that applied the earlier fix were already protected, but teams that delayed because they saw it as a lower-priority DoS issue may now face a much higher-risk situation.
What versions are affected and what admins should do now
NVD lists the flaw as critical, with F5 CNA scores of 9.3 in CVSS v4.0 and 9.8 in CVSS v3.1. The public description says the issue affects BIG-IP APM when an access policy is configured on a virtual server.
Public F5 release notes and related vendor references point to patched branches including 15.1.10.8, 16.1.6.1, 17.1.3, 17.5.1.3, and 21.0.0, depending on the supported train in use. Older versions that reached end of technical support were not evaluated, which means some legacy deployments may remain especially risky.
F5 has also published indicators of compromise tied to related malicious activity, and third-party reporting says attackers have used the bug to deploy web shells. For defenders, that means patching alone may not be enough. Teams should patch, then review logs, check exposed assets, and hunt for signs of post-exploitation.
CVE-2025-53521 at a glance
| Item | Details |
|---|---|
| CVE | CVE-2025-53521 |
| Product | F5 BIG-IP Access Policy Manager (APM) |
| Current impact | Remote code execution |
| Exploitation status | Actively exploited |
| CISA KEV added | March 27, 2026 |
| Federal due date | March 30, 2026 |
| Severity | Critical |
| Key exposure data point | 17,100+ internet-exposed APM instances seen on March 31, 2026 |
| Main risk | Attackers can compromise edge infrastructure and pivot deeper into internal networks |
What security teams should prioritize
- Patch every exposed BIG-IP APM instance on a supported branch immediately.
- Treat internet-facing APM appliances as potentially compromised if they remained exposed after public exploitation began.
- Review F5โs IoC guidance and inspect systems for suspicious files, web shells, or abnormal access behavior.
- Inventory all external access gateways and verify that no forgotten or secondary APM interface remains online.
- Flag unsupported BIG-IP versions for urgent replacement or isolation because F5 did not evaluate end-of-support releases.
FAQ
It is a critical vulnerability in F5 BIG-IP APM. F5 now describes it as an issue where specific malicious traffic can lead to remote code execution when an APM access policy is configured on a virtual server.
Yes. CISA added it to the Known Exploited Vulnerabilities catalog on March 27, 2026, which signals evidence of active exploitation.
Because the flaw was first presented as a denial-of-service issue, then later recategorized as remote code execution. That changed how defenders and attackers viewed its impact.
Shadowserver said it saw more than 17,100 exposed instances on March 31, 2026. Some reports based on that dataset said more than 14,000 systems still appeared exposed after partial patching.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages