thehackernews.com 3/28/2026, 7:38:56 AM · via preferred

CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation

CVE-2025-53521: F5 BIG-IP APM Flaw Reclassified as Unauthenticated RCE

CVE-2025-53521 is a vulnerability in F5 BIG-IP Access Policy Manager (APM) that was reclassified in 2026 from a denial-of-service issue to an unauthenticated remote code execution (RCE) vulnerability. The flaw is actively exploited, with exploitation occurring in vulnerable BIG-IP versions and CISA listing it in its Known Exploited Vulnerabilities catalog.…

First seen 2026-03-27T22:10:57.047Z · Last seen 2026-04-01T11:42:56.200Z

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

ACCORDING to The Hacker News, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-53521 to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation of F5 BIG-IP Access Policy Manager (APM). The vulnerability could allow a threat actor to achieve remote code execution, with CVSS v4 score 9.3, and was described as pre-auth remote code execution in the current advisories.

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to remote code execution, according to CVE[.]org. The flaw was initially categorised as a denial-of-service issue but was reclassified as RCE in light of new information obtained in March 2026, and F5 subsequently updated its advisory to confirm exploitation in the vulnerable BIG-IP versions.

In response to the active exploitation, Federal Civilian Executive Branch agencies have been given until 30 March 2026 to apply fixes to secure their networks.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline