CVE-2025-53521: critical vulnerability in F5 BIG-IP
BigIP APM Vulnerability
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
A flaw in F5 BIG-IP's APM (Access Policy Manager) allows attackers to run malicious code remotely on affected servers when certain traffic patterns are sent. This is a critical vulnerability because it gives attackers complete control over the system.
A stack-based buffer overflow (CWE-121) in BIG-IP APM's access policy processing allows unauthenticated remote code execution when specially crafted traffic is sent to a virtual server with APM enabled. The vulnerability requires no authentication or user interaction and can be exploited with network-level access to the vulnerable interface.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.