Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks
ID: 09728535-9fca-5b28-88de-64a6258289be
STIX ID: report--09728535-9fca-5b28-88de-64a6258289be
Feed Name: Bleeping Computer
Threat Score
A 5-month-old F5 BIG-IP APM flaw (CVE-2025-53521), recently reclassified from a DoS to a critical RCE, is being actively exploited in the wild; threat monitors report over 17,000 BIG-IP APM fingerprints online with more than 14,000 systems still exposed, CISA has added the vulnerability to its actively exploited list, and F5 has published IOCs and remediation guidance including recommending rebuilding compromised devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
