14,000+ F5 BIG-IP APM Instances Exposed Online as Attackers Exploit RCE Vulnerability
ID: d96e7a6c-14d1-57fd-9d3f-6a643113aca9
STIX ID: report--d96e7a6c-14d1-57fd-9d3f-6a643113aca9
Feed Name: GBHackers
Threat Score
The report warns that CVE-2025-53521 in F5 BIG-IP APM has been escalated from a DoS to an unauthenticated Remote Code Execution vulnerability with confirmed active exploitation; CISA has listed it in its KEV catalog and Shadowserver found over 17,100 internet-exposed appliances, so organizations must urgently apply patches, restrict management access, review logs, monitor traffic, and enable MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
