Story perspectives
CISA Warns: Critical F5 BIG-IP Vulnerability Requires Urgent Fixes
3/30/2026
1 of 1
Story summary
- Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-53521 to the Known Exploited Vulnerabilities catalog for F5 BIG-IP Access Policy Manager (APM).
- The vulnerability is active and carries a CVSS 9.3.
- It was initially a denial-of-service issue and is now a remote code execution risk.
- F5 has provided indicators of compromise to help organizations assess exposure.
- CISA urges federal agencies to apply fixes within three days as the situation escalates.
