Feeds2.Feedburner Active Exploitation of RCE Vulnerability in F5 BIG-IP APM Systems
Article Content
- •CVE-2025-53521 is a critical RCE vulnerability in F5 BIG-IP APM systems.
- •CISA added the vulnerability to its KEV catalog due to active exploitation.
- •The vulnerability has a CVSS score of 9.8, highlighting its severity.
A critical unauthenticated remote code execution vulnerability, tracked as CVE-2025-53521, in F5's BIG-IP Access Policy Manager (APM) systems is currently being exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog on March 27, 2026, following an update from F5 regarding a data breach attributed to a sophisticated nation-state threat actor. The vulnerability has a CVSS score of 9.8, indicating its high severity. Organizations using F5 BIG-IP APM systems are at risk, as the flaw allows attackers to execute arbitrary code without authentication. F5 initially published a security advisory on October 15, 2025, when the breach was confirmed. The ongoing exploitation poses a significant threat to affected systems and their users.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (23)
Following this threat?
Track CVE-2025-53521 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…