Attackers Exploit RCE Flaw as 14,000 F5 BIG-IP APM Instances Remain Exposed
ID: 2758b824-0251-55cf-a8e6-7d6eba9f4518
STIX ID: report--2758b824-0251-55cf-a8e6-7d6eba9f4518
Feed Name: Security Affairs
Threat Score
Over 14,000 F5 BIG-IP APM instances remain exposed and are being actively exploited via a critical RCE vulnerability **CVE-2025-53521** (CVSS 9.8). Shadowserver reports ~14,100 exposed IPs (mostly in the US, Europe, and Asia); CISA added the flaw to its KEV catalog and ordered federal agencies to remediate by March 30, 2026. The vendor's original fix remains effective, but exploitation of vulnerable BIG-IP versions is ongoing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
