This text was generated using artificial intelligence (AI).CVE-2025-53521 affects F5 BIG-IP Access Policy Manager (APM). F5 reclassified the vulnerability as a remote code execution issue in March 2026. F5 and CISA confirm active exploitation; CISA included CVE-2025-53521 in their catalog of known actively exploited security vulnerabilities at the end of March 2026.
Exploitation requires a BIG-IP APM access policy to be configured on a virtual server. Specific malicious traffic could allow an unauthenticated attacker to execute code via the process apmd .
The following BIG-IP APM release series are affected:
17.5.0 to 17.5.1
17.1.0 to 17.1.2
16.1.0 to 16.1.6
15.1.0 to 15.1.10
F5 provides fixes in releases 17.5.1.3, 17.1.3, 16.1.6.1, and 15.1.10.8. Details about the respective releases are documented in the F5 Security Advisory K000156741.
From Denial of Service to Remote Code Execution
The vulnerability was initially published in October 2025 as a denial-of-service issue with a CVSS v4.0 score of 8.7. After reassessment in March 2026, it is listed as a remote code execution vulnerability. The CVSS v4.0 score is 9,3; the NVD entry shows a CVSS v3.1 score of 9,8 from.
The vulnerability affects the data plane. Compromise of the control plane is not documented. BIG-IP systems in appliance mode are also affected.
F5 additionally documents web shell activity following successful compromises. Therefore, the assessment should include not only updates but also checks for potential activity following an attack.
Prioritization and Technical Measures
Updating to a fixed release is the priority measure. For prioritization, BIG-IP APM instances whose virtual servers are accessible over external networks and use APM access policies are particularly relevant.
If an immediate update is not possible, F5 recommends restricting access to affected virtual servers. Additionally, teams should review F5's published notices on suspicious files, unusual log entries, and HTTP/S traffic patterns.
A technical review should cover the following points:
restrict access to affected virtual servers unless an update has been performed,
investigate indications of web shells and other suspicious activities according to F5 Advisory.
DACH and EU Context
Organizations in Germany and Austria that fall under NIS-2 obligations — implemented in Austria through the NISG — should prioritize CVE-2025-53521 as a critical vulnerability in network-exposed infrastructure. For Swiss organizations, the reporting obligation under the revised Information Security Act (ISG) applies to the BACS. If a data breach involving personal data is found during the investigation of a compromise, the 72-hour reporting obligation under Art. 33 GDPR also applies.
For CVE-2025-53521, the visibility of externally accessible BIG-IP-APM instances is a relevant part of the prioritization. LocateRisk can reveal exposed assets and deployed software under customer-owned domains. This can include TLS certificates, HTTP banners, and APM login pages as external characteristics.
However, the external visibility of a system does not alone prove the specifically vulnerable installed version or the configuration of an APM access policy. These points require examination of the systems and configurations by the responsible team.
In a reassessment like with CVE-2025-53521, External Attack Surface Management assists in assigning externally accessible BIG-IP-APM instances to a prioritized review list. For deployed technologies and dependencies, Vendor Risk Management can complement the organizational assessment.
Am I affected?
This affects F5 BIG-IP APM in the versions mentioned above; the vulnerability was fixed in 17.5.1.3, 17.1.3, 16.1.6.1, 15.1.10.8. If you want to know whether F5 BIG-IP APM is even visible in your externally accessible infrastructure, you can find the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2025-53521 is a vulnerability in F5 BIG-IP Access Policy Manager (APM). It allows an unauthenticated attacker to execute remote code when an APM access policy is configured on a virtual server. The vulnerability was originally classified in October 2025 as a denial-of-service issue and reclassified in March 2026 as an RCE vulnerability.
This affects the release series 15.1.0–15.1.10, 16.1.0–16.1.6, 17.1.0–17.1.2, and 17.5.0–17.5.1. F5 has released fixes in versions 15.1.10.8, 16.1.6.1, 17.1.3, and 17.5.1.3. BIG-IP systems in appliance mode are also affected.
F5 has published indicators of a compromise, including suspicious files on the system, unusual log entries, and irregular HTTP/S traffic patterns. After successful exploitation, web shells were used in practice. Teams should perform the validation steps described in the F5 Advisory K000156741.
Status: September 22, 2026. This article is for general informational purposes only and is not legal, security, or action advice for individual cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always decisive. Despite careful research, we assume no liability for the timeliness, correctness, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2025-53521
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.