logo

14,000+ F5 BIG-IP APM Instances Exposed Online as Attackers Exploit RCE Vulnerability

ID: d96e7a6c-14d1-57fd-9d3f-6a643113aca9

STIX ID: report--d96e7a6c-14d1-57fd-9d3f-6a643113aca9

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: Divya

...
...

The report warns that CVE-2025-53521 in F5 BIG-IP APM has been escalated from a DoS to an unauthenticated Remote Code Execution vulnerability with confirmed active exploitation; CISA has listed it in its KEV catalog and Shadowserver found over 17,100 internet-exposed appliances, so organizations must urgently apply patches, restrict management access, review logs, monitor traffic, and enable MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.