Drooid Logo
Back to story perspectives

Full Breakdown

Critical F5 BIG-IP Vulnerability CVE-2025-53521 Exploited in the Wild

3/30/2026, 8:14:00 PM

Overview of the Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw, CVE-2025-53521, to its Known Exploited Vulnerabilities (KEV) catalog, following evidence of active exploitation. This vulnerability affects F5 BIG-IP Access Policy Manager (APM) systems, allowing unauthenticated attackers to achieve remote code execution (RCE). Initially disclosed in October 2025 as a denial-of-service (DoS) issue with a CVSS score of 8.7, it was reclassified to RCE with a score of 9.3 in March 2026 due to new information.

Technical Details

CVE-2025-53521 impacts several versions of F5 BIG-IP APM, specifically versions 17.5.0 to 17.5.1, 17.1.0 to 17.1.2, 16.1.0 to 16.1.6, and 15.1.0 to 15.1.10. F5 has released patches in versions 17.5.1.3, 17.1.3, 16.1.6.1, and 15.1.10.8. The vulnerability can be exploited when a BIG-IP APM access policy is configured on a virtual server, leading to potential RCE through specific malicious traffic.

F5 has provided indicators of compromise (IOCs) to help organizations identify potential exploitation. These include the presence of rogue files, mismatches in file hashes, and specific log entries indicating unauthorized access to the iControl REST API.

Urgency and Response

In light of the ongoing exploitation, CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies apply the necessary patches by March 30, 2026. Benjamin Harris, CEO of watchTowr, emphasized the shift in risk profile, stating, “Fast forward to today's big 'yikes' moment: the situation has changed significantly.” This reflects a growing concern among cybersecurity experts regarding the vulnerability's implications.

Observations from the Field

Defused Cyber has reported an increase in scanning activity targeting vulnerable F5 BIG-IP devices since the vulnerability's addition to the KEV catalog. They noted that attackers are probing the /mgmt/shared/identified-devices/config/device-info endpoint, which retrieves critical system information.

Criticism and Concerns

Experts have expressed concern over the initial classification of CVE-2025-53521 as a DoS issue, which may have led to inadequate prioritization of remediation efforts by system administrators. The reclassification to RCE has raised alarms about the potential for widespread exploitation.

Official Statements

F5 has acknowledged the severity of the vulnerability and confirmed that it has been exploited in the wild. They have updated their advisory to reflect the RCE risk and provided detailed indicators for organizations to assess potential compromises.

Verbatim Quotes

  • “This vulnerability allows an unauthenticated attacker to perform remote code execution.” — F5 Advisory
  • “Fast forward to today's big 'yikes' moment: the situation has changed significantly.” — Benjamin Harris, CEO of watchTowr
  • “We have observed cases of webshell being written to disk; however, the webshells have been observed to work in memory only, meaning the files listed above might not be modified,” — F5 Advisory

Conclusion

The emergence of CVE-2025-53521 as a critical RCE vulnerability underscores the importance of timely patching and vigilance in cybersecurity practices. Organizations are urged to prioritize the application of fixes to mitigate the risks associated with this vulnerability.