logo

CISA Issues Three-Days Patch Mandate for Critical 9.8 F5 BIG-IP RCE

ID: 4710a545-6348-5ca7-ac63-ee56f79661ca

STIX ID: report--4710a545-6348-5ca7-ac63-ee56f79661ca

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-29

Date Updated: 2026-04-23

Author: Ddos

...
...

CISA has added a critical RCE vulnerability (CVE-2025-53521, CVSS 9.8) affecting F5 BIG-IP Access Policy Manager to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; federal agencies are mandated to remediate by March 30, 2026, and organizations are urged to patch or migrate unsupported versions to prevent interception of encrypted traffic, lateral movement, and persistent access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.