logo

Attackers Exploit RCE Flaw as 14,000 F5 BIG-IP APM Instances Remain Exposed

ID: 2758b824-0251-55cf-a8e6-7d6eba9f4518

STIX ID: report--2758b824-0251-55cf-a8e6-7d6eba9f4518

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-04-06

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Over 14,000 F5 BIG-IP APM instances remain exposed and are being actively exploited via a critical RCE vulnerability **CVE-2025-53521** (CVSS 9.8). Shadowserver reports ~14,100 exposed IPs (mostly in the US, Europe, and Asia); CISA added the flaw to its KEV catalog and ordered federal agencies to remediate by March 30, 2026. The vendor's original fix remains effective, but exploitation of vulnerable BIG-IP versions is ongoing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.