CVE-2025-53521: Active RCE in F5 BIG-IP APM

This text was generated using artificial intelligence (AI).CVE-2025-53521 affects F5 BIG-IP Access Policy Manager (APM). F5 reclassified the vulnerability as a remote code execution issue in March 2026. F5 and CISA confirm active exploitation; CISA included CVE-2025-53521 in their catalog of known actively exploited security vulnerabilities at the end of March 2026.

Exploitation requires a BIG-IP APM access policy to be configured on a virtual server. Specific malicious traffic could allow an unauthenticated attacker to execute code via the process apmd .

Are my systems affected? Check now →