logo

Attackers are exploiting RCE vulnerability in BIG-IP APM systems (CVE-2025-53521)

ID: cf31a406-d15a-53a0-a2d5-6d23eb7582a6

STIX ID: report--cf31a406-d15a-53a0-a2d5-6d23eb7582a6

Feed Name: Help Net Security

Threat Score
92/100

Date Published: 2026-03-28

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

A critical unauthenticated RCE (CVE-2025-53521) in F5 BIG-IP Access Policy Manager is being actively exploited; F5 disclosed a related October 2025 data breach in which a sophisticated nation-state actor accessed BIG-IP source code and may have deployed a backdoor (Brickstorm) against customers. Patches were released but evidence of in-the-wild exploitation, webshells, and modifications to system integrity checks has prompted CISA to add the flaw to its Known Exploited Vulnerabilities catalog and order federal agencies to assess and mitigate exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.