logo

14,000+ F5 BIG-IP APM Devices Exposed Online Amid Active RCE Vulnerability Exploits

ID: 5a35b2c5-a663-5ce0-a976-d4ffe690fa00

STIX ID: report--5a35b2c5-a663-5ce0-a976-d4ffe690fa00

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-03

Date Updated: 2026-05-05

Author: Abinaya

...
...

A serious Remote Code Execution vulnerability (CVE-2025-53521) in F5 BIG-IP APM — previously classified as a DoS — is being actively exploited; Shadowserver telemetry found over 17,100 exposed instances worldwide (more than 14,000 still internet-accessible), CISA added the flaw to its KEV catalog, and organizations are urged to apply F5 patches, hunt for indicators of compromise, and audit exposed assets immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.