logo

CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation

ID: a56d5ce5-77c1-5297-a8ec-0c1880b7e231

STIX ID: report--a56d5ce5-77c1-5297-a8ec-0c1880b7e231

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-28

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA added CVE-2025-53521 — a critical F5 BIG-IP APM flaw now understood to allow pre-auth remote code execution (CVSS v4 9.3) — to its KEV catalog citing in-the-wild exploitation. F5 updated advisories and published IOCs and TTPs (file/hash mismatches, modified webtop renderer files, webshell activity in memory, specific HTTP response patterns); multiple BIG-IP versions are impacted and federal agencies were given an urgent patch deadline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.