Skip to content

CVE-2025-53521

CVE

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
March 28, 2026
Last Seen
September 23, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth pr...

A critical unauthenticated remote code execution vulnerability, tracked as CVE-2025-53521, in F5's BIG-IP Access Policy Manager (APM) systems is currently being exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities...

A sophisticated Linux implant targeting F5 BIG-IP Access Policy Management (APM) environments has been identified, exploiting CVE-2025-53521, an unauthenticated remote code execution vulnerability. This malware, referred to as 'PoisonedRefresh,' employs advanced techniques like function hooking and...

Public Exploits

Checking GitHub for proof-of-concept code…