logo

CVE-2025-53521: F5 BIG-IP APM Flaw Reclassified as Unauthenticated RCE

ID: e5d9e1ac-4198-5200-9363-5867148e424a

STIX ID: report--e5d9e1ac-4198-5200-9363-5867148e424a

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

**Executive summary:** CVE-2025-53521 is a high-severity (CVSS 9.8) vulnerability in F5 BIG-IP APM that can allow unauthenticated remote code execution when an APM access policy is bound to a virtual server; it is actively exploited in the wild, affects multiple BIG-IP version branches (15.1.x, 16.1.x, 17.1.x, 17.5.x) with specified fixed releases, and the report provides IOCs, detection tips, and prioritized remediation and recovery guidance including patching, configuration scoping, compromise assessments, and credential rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.