CVE-2025-53521

Published Oct 15, 2025

Last updated 6 months ago

Exploit knownCVSS critical 9.3
Network
IoT
Supply chain
VPN
Server
OT
Port (22)
BIG-IP APM
BIG-IP

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-53521 is a vulnerability affecting F5 BIG-IP Access Policy Manager (APM) systems when an access policy is configured on a virtual server. The flaw, categorized as CWE-770 (Allocation of Resources Without Limits or Throttling), allows undisclosed or specially crafted traffic to cause the Traffic Management Microkernel (TMM) process to terminate. This termination of the TMM process results in a disruption of all traffic handled by the BIG-IP device until the process restarts. The vulnerability can be exploited remotely by an unauthenticated attacker, leading to a denial-of-service condition on the BIG-IP APM system.

Description
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source
f5sirt@f5.com
NVD status
Analyzed
Products
big-ip_access_policy_manager

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
F5 BIG-IP Unspecified Vulnerability
Exploit added on
Mar 27, 2026
Exploit action due
Mar 30, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

f5sirt@f5.com
CWE-121

Social media

Hype score
Not currently trending
  1. An F5 BIG-IP APM rootkit (named PoisonedRefresh by ESET) hooks Apache and PHP at runtime to serve a web shell that never touches disk, exploiting CVE-2025-53521, an unauthenticated RCE now in CISA KEV. - CVE-2025-53521 is the door. An unauthenticated RCE in BIG-IP APM, added to

    @DFIR_Radar

    14 Sept 2026

    246 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  2. 🟠 𝗛𝗜𝗚𝗛 · 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 🏢 Target: 𝗙𝟱 𝗡𝗲𝘁𝘄𝗼𝗿𝗸𝘀 A Linux rootkit targeting F5 BIG-IP APM devices has been identified, capable of injecting a web shell into memory without writing to disk. This malware exploits a critic

    @intels_daily

    11 Sept 2026

    121 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ⚠️⚠️ CVE-2025-53521 (CVSS 9.8): Unauthenticated RCE in F5 BIG-IP APM (apmd) — now being exploited to drop the PoisonedRefresh memory-only Linux rootkit on SSL-VPN appliances. 🔗FOFA Link: https://t.co/cQvguyFmL5 🎯1.6M+ Results are found on https://t.co/pb16tGXCUG i

    @fofabot

    11 Sept 2026

    2736 Impressions

    12 Retweets

    31 Likes

    16 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-53521, discovered in October of 2025 as a minor technical glitch, has recently been escalated to CVSS 9.3 due to its ability to perform RCE. This vulnerability affects F5's BIG-IP access policy manager when policies are set on virtual servers. The exploit utilizes a

    @Leila97726926

    10 Sept 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Investigadores de Sophos alertan: el malware c05d5254 esconde una web shell PHP en memoria para evadir escaneos. Los atacantes lo usan tras explotar CVE-2025-53521 (CVSS 9.8) sin login en F5 BIG-IP. Parchea y monitorea. https://t.co/OVG32Sop6G https://t.co/BCYd9lr1Dx

    @ProtAAPP

    10 Sept 2026

    268 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. #threatreport #LowCompleteness Dissecting a PHP web server rootkit | 07-09-2026 Source: https://t.co/uyP062Rd9R Key details below ↓ 💀Threats: Chinachopper, 🎯Victims: Big ip access policy management webtop environments 🔓CVEs: CVE-2025-53521 https://t.co/nQ1MtmVDwo

    @rst_cloud

    10 Sept 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Prasówka 10.09 Wyszedł OpenSSL w wersji 4.1 alpha1: DTLS 1.3, GREASE, IKEv2 KDF, szybsze ML-KEM i ML-DSA. Tylko do testów. PoisonedRefresh: bezplikowy rootkit działający na Apache (CVE-2025-53521) wstrzykuje webshell do pamięci. Update nie pomaga. i-have-adhd: projekt, k

    @arkady86

    10 Sept 2026

    282 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  8. 🟠 𝗛𝗜𝗚𝗛 · 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 🏢 Target: 𝗙𝟱 🧩 Product: 𝗙𝟱 𝗕𝗜𝗚-𝗜𝗣 𝗔𝗣𝗠 A detailed analysis of the PoisonedRefresh Linux implant targeting F5 BIG-IP APM systems, exploiting CVE-2025-53521 for unauthorized command exe

    @intels_daily

    9 Sept 2026

    106 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. TRC analysis shows attackers exploiting CVE-2025-53521 in F5 BIG-IP APM to inject PHP web shells directly into Apache memory, bypassing disk-based detection entirely. The malware hooks system functions to modify scripts in-memory and establishes C2 through disguised HTTP

    @aviatrixtrc

    9 Sept 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. PoisonedRefresh is a fileless Linux implant that provides web-shell and interactive shell access on compromised F5 BIG-IP APM systems. - Initial access exploits unauthenticated remote code execution in CVE-2025-53521. - A first-stage payload modifies system components, SELinux h

    @LandscapeThreat

    9 Sept 2026

    46 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Hackers deployed a Linux rootkit on F5 BIG-IP APM devices, keeping a web shell in memory to evade file-based detection. The campaign is linked to CVE-2025-53521 and PoisonedRefresh. #F5BIGIPAPM #CVE202553521 #PoisonedRefresh https://t.co/eJU8oc0Txk

    @TweetThreatNews

    9 Sept 2026

    207 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. PoisonedRefresh is a fileless Linux rootkit targeting F5 BIG-IP APM, injecting PHP web shells entirely into Apache process memory via CVE-2025-53521, an actively exploited unauthenticated RCE. - CVE-2025-53521 is the initial access vector: an unauthenticated RCE in BIG-IP APM ht

    @DFIR_Radar

    9 Sept 2026

    270 Impressions

    1 Retweet

    3 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  13. Sophos found F5 BIG-IP APM malware injecting a PHP web shell into memory, leaving disk files clean. Linked to CVE-2025-53521 and c05d5254, with indicators like apm_css.php3 and full_wt.php3. #F5 #BIGIPAPM #CVE202553521 https://t.co/DmKbsyd2lR

    @TweetThreatNews

    9 Sept 2026

    186 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Alert for admins: new malware infects F5 BIG-IP APM via CVE-2025-53521 — instead of dropping files on disk, it injects a PHP web shell into memory when Apache loads certain scripts (apm_css.php3, full_wt.php3, webtop_popup_css.php3). It also alters core binaries, disables https

    @dailytechonx

    9 Sept 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Sophos found a Linux rootkit in F5 BIG-IP APM that hooks Apache/PHP, injects a fileless web shell into memory, and may follow CVE-2025-53521 exploitation. #F5BIGIP #PoisonedRefresh #CVE202553521 https://t.co/ljBe4l3loX

    @TweetThreatNews

    8 Sept 2026

    198 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🔴 F5 BIG-IP APM cihazlarını hedefleyen gelişmiş bir Linux rootkit ortaya çıktı! Sophos araştırmacıları, CVE-2025-53521 sonrasında dağıtıldığı değerlendirilen bir rootkit'in Apache/PHP çalışma mekanizmasını hook ederek belleğe fileless web shell enjekt

    @ridvanyagli

    8 Sept 2026

    324 Impressions

    0 Retweets

    1 Like

    2 Bookmarks

    0 Replies

    0 Quotes

  17. F5 BIG-IP APM devices are being hit with a Linux rootkit (ESET: PoisonedRefresh) that hooks PHP loading and injects a fileless in-memory web shell. Sophos ties it to post-exploitation of CVE-2025-53521 and notes persistence across BIG-IP upgrade images.

    @XavierRiveraX

    8 Sept 2026

    88 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. News: F5 BIG-IP APM rootkit (PoisonedRefresh) injects a fileless PHP web shell after CVE-2025-53521 RCE. Persists across upgrades. ~795 hosts exposed. Patch APM; watch .php3 POSTs that return HTTP 201 as CSS. https://t.co/9ku4Yl4rvx

    @snakeyesV1

    8 Sept 2026

    93 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  19. A fileless PHP web shell implant targeting F5 BIG-IP APM systems uses custom ELF loading, APR function hooking, and in-memory mmap patching to deliver attacker access with zero on-disk web shell artifacts. Key findings: - CVE-2025-53521 is the initial access vector: an https://

    @DFIR_Radar

    7 Sept 2026

    194 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  20. We are scanning & reporting F5 BIG-IP APM CVE-2025-53521 instances thanks to collaboration with the @ncsc_nl SRT. 10 months after vuln disclosure, we still see over 850 IPs vulnerable to potential RCE. Top affected: US with 199 & Japan 182. IP data in Vulnerable HTTP repo

    @Shadowserver

    14 Aug 2026

    1429 Impressions

    5 Retweets

    9 Likes

    3 Bookmarks

    2 Replies

    0 Quotes

  21. TRC analysis reveals attackers chaining F5 BIG-IP and Confluence exploits to pivot from edge appliances into Active Directory. CVE-2025-53521 provided initial access, followed by credential harvesting for relay authentication attacks. Runtime segmentation could have limited this

    @aviatrixtrc

    23 May 2026

    267 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Approximately a month ago, F5 published advisory on malware deployed to BIG-IP systems vulnerable to CVE-2025-53521. #ESETresearch discovered two related malware components on VirusTotal and named the threat #PoisonedRefresh. 1/6 https://t.co/OfekbKd8a9

    @ESETresearch

    24 Apr 2026

    4119 Impressions

    12 Retweets

    36 Likes

    15 Bookmarks

    1 Reply

    1 Quote

  23. 🚨 [CRITICAL] Critical RCE Vulnerability in F5 BIG-IP Access Policy Manager Under Active Exploitation The UK NCSC has issued an urgent advisory regarding CVE-2025-53521, an unauthenticated remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager (APM). htt

    @HalluG76811

    21 Apr 2026

    136 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. F5 BIG-IP 긴급 패치, CVE-2025-53521 (출처 : 기록 | https://t.co/4mrWqpidcJ 블로그) https://t.co/nVerHLLeB7

    @J_zjaan7946

    17 Apr 2026

    157 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🔒 #CyberSecurity CVE-2025-53521: F5 BIG-IP Unauthenticated RCE — Detection and Emergency Hardeni… "On March 27, 2026, CISA added CVE-2025-53521 to its Known Exploited Vulnerabilities (KEV)…" 🔗 https://t.co/MhFNGwwQQi #CyberSecurity #ThreatIntel #vulnerability #cve

    @SecurityAr58409

    15 Apr 2026

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 🔒 #CyberSecurity Immediate Action Required: Patching F5 BIG-IP APM Against CVE-2025-53521 "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security…" 🔗 https://t.co/50qmp9rWtt #CyberSecurity #ThreatIntel #vulnerability #cve #patch

    @SecurityAr58409

    15 Apr 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 🔒 #CyberSecurity Urgent: Defending Against Active Exploitation of F5 BIG-IP APM (CVE-2025-53521) "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm by…" 🔗 https://t.co/KdSlD7OTQ2 #CyberSecurity #ThreatIntel #vulnerability #cve #pat

    @SecurityAr58409

    15 Apr 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. F5 has updated its security advisory for a vulnerability impacting BIG-IP APM that was originally disclosed in October 2025 (CVE-2025-53521). Learn more in our latest security bulletin: https://t.co/jmxqUJFEdG

    @ChannelSkell

    14 Apr 2026

    89 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. ثـ ـغرة CVE-2025-53521 في F5 BIG-IP APM تدخل قائمة CISA للثـ ـغرات المستغلة التفاصيل .. https://t.co/Q3M9WECM7s #مركز_الأمن_السيبراني_للابحاث_والدراسات https://t.co/UQ4lP3M55S

    @ccforrs

    10 Apr 2026

    118 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. CVE-2025-53521: 2025 vuln, 2026 RCE reclassification, active exploitation. 14K BIG-IP APM instances still on internet. F5 publishes IOCs and says "rebuild." When the vendor says rebuild, patching is theater. Your appliance is compromised. Question: why was it exposed?

    @CisoRaging77913

    10 Apr 2026

    119 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. F5 BIG-IP APM の RCE 脆弱性 CVE-2025-53521:実環境での積極的な悪用を確認 https://t.co/zwywf9Dtu3 この問題の原因は、脆弱性 CVE-2025-53521 に対する初期の分類が、サービス拒否 (DoS) とされていた点にあります。一般的に、

    @iototsecnews

    10 Apr 2026

    198 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. F5 has updated its security advisory regarding a vulnerability affecting BIG-IP APM that was originally disclosed in October 2025 (CVE-2025-53521). For more information, please see our latest security bulletin: https://t.co/ZJHoVjPYXs

    @rfrumm

    8 Apr 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. ⚠️ **Vulnerability Alert:** F5 BIG-IP Access Policy Manager Stack-based Buffer Overflow (CVE-2025-53521) — Actively Exploited RCE 📅 **Timeline:** Disclosure: 2025-04-08, Patch: 2025-04-08 🆔 **CVE-2025-53521** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 97.39% 🛠

    @syedaquib77

    8 Apr 2026

    123 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 統合版 JPCERT/CC | Weekly Report: F5 BIG-IP Access Policy Managerの脆弱性(CVE-2025-53521)に関する注意喚起 https://t.co/Qf7Ag9QiAK #itsec_jp

    @itsec_jp

    8 Apr 2026

    158 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. ⚠️ Stop scrolling if your company uses F5 BIG-IP APM Critical flaw CVE-2025-53521 is now on CISA’s KEV list—and already exploited. Attackers can run code remotely, steal data, and take over systems. Patch immediately. Don’t wait.

    @TheCyberse46292

    7 Apr 2026

    111 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 🚨 Edge infrastructure is failing first — again. CISA just added two critical flaws to the KEV catalog: • Citrix NetScaler CVE-2026-3055 (memory overread via SAML IdP) • F5 BIG-IP APM CVE-2025-53521 (unauthenticated RCE) Both are actively exploited. New article → htt

    @ByteVanguardSec

    7 Apr 2026

    113 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. F5 hat seinen Sicherheitshinweis zu einer Sicherheitslücke aktualisiert, die BIG-IP APM betrifft und ursprünglich im Oktober 2025 bekannt gegeben wurde (CVE-2025-53521). Weitere Informationen finden Sie in unserem aktuellen Sicherheitsbulletin: https://t.co/ZBCqQ0TS2E

    @rfrumm

    7 Apr 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Attackers are actively exploiting CVE-2025-53521, a critical RCE in F5 BIG-IP APM, with Shadowserver identifying over 14,000 exposed instances globally after the flaw was reclassified from DoS to remote code execution and added to CISA’s KEV catalog. https://t.co/sNWUY2Y65O

    @VivekIntel

    6 Apr 2026

    165 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  39. CISA flags active F5 BIG-IP exploit. 🔗 https://t.co/SMp0zi7QPO CVE-2025-53521 enables unauthenticated remote code execution and full system compromise. KEV listing means urgent patching is required. #MADSecurity #CISA #Cybersecurity #VulnerabilityManagement

    @MADSecurityLLC

    6 Apr 2026

    119 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. ⚠️ Threat Update: F5 BIG-IP APM RCE Exploitation (CVE-2025-53521) 📝 Key Updates Summary: NEW: CVE-2025-53521 was reclassified in Mar 2026 from DoS to unauthenticated RCE and added to CISA's KEV (3/27/2026) with a federal remediation directive. NEW: Shadowserver snapshots

    @syedaquib77

    6 Apr 2026

    151 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. 【F5 BIG-IP APMの重大RCE、14,000超がなお露出】 F5 BIG-IP APMのRCE脆弱性 CVE-2025-53521 はすでに悪用が確認されており、なお14,000台超の公開インスタンスが残っていると報じられています。 未認証RCEにつながる深刻な

    @01ra66it

    6 Apr 2026

    276 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  42. ⚠️ Threat Update: Active Exploitation of CVE-2025-53521 Against F5 BIG-IP APM 📝 Key Updates Summary: NEW: 2026-04-06 incoming report corroborates active exploitation of CVE-2025-53521 and provides a Shadowserver exposure snapshot (~14,100 exposed APM fingerprints across

    @syedaquib77

    6 Apr 2026

    128 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. Attackers Exploit RCE Flaw as 14,000 F5 BIG-IP APM Instances Remain Exposed: Over 14,000 F5 BIG-IP APM instances remain exposed online, as attackers actively exploit a critical remote code execution flaw CVE-2025-53521. Over 14,000 F5 BIG-IP APM… https://t.co/zpLPylrt46 https:/

    @shah_sheikh

    6 Apr 2026

    113 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. [Security Affairs] Attackers Exploit RCE Flaw as 14,000 F5 BIG-IP APM Instances Remain Exposed. Over 14,000 F5 BIG-IP APM instances remain exposed online, as attackers actively exploit a critical remote code execution flaw CVE-2025-53521. Over 14,000... https://t.co/sqwmBHZnU3

    @shah_sheikh

    6 Apr 2026

    108 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. turns into an actively exploited F5 BIG-IP APM… (CVE-2025-53521) is a good reminder that this vulnerability can turn edge and identity infrastructure into a much bigger remote code execution problem. For defenders, the priority is to validate exposure, watch for suspic…

    @SocXAInvaders

    6 Apr 2026

    137 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. turns into an actively exploited F5 BIG-IP APM… (CVE-2025-53521) is a vulnerability story defenders should take serious… F5 has reclassified the vulnerability from a denial of service issue to remote code execution , confirmed exp…

    @fynn_JourX

    6 Apr 2026

    136 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. For defenders, cve-2025-53521 turns into an actively exploited f5 big-ip apm r… should move fast. F5 reclassified CVE-2025-53521 from DoS to remote code execution, CISA added it to KEV, and… 🔗 Details → https://t.co/ivyyW0SUmB

    @SocXAInvaders

    6 Apr 2026

    133 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. Legacy exposure keeps paying off for attackers. CVE-2025-53521 turns into an actively exploited F5 BIG-IP… F5 reclassified CVE-2025-53521 from DoS to remote code execution, CISA added it to KEV, and… 🔗 Read → https://t.co/qAubleY76J

    @fynn_JourX

    6 Apr 2026

    132 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. turns into an actively exploited F5 BIG-IP APM… (CVE-2025-53521) deserves defender attention because this vulnerability… F5 has reclassified the vulnerability from a denial of service issue to remote code execution , confirmed exp…

    @lucasverdan

    6 Apr 2026

    159 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. 🛑 CVE-2025-53521 turns into an actively exploited F5 BIG-IP APM RCE F5 reclassified CVE-2025-53521 from DoS to remote code execution, CISA added it to KEV, and… 🔗 Details → https://t.co/TUf0xBbEnS

    @lucasverdan

    6 Apr 2026

    136 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations