Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Advisory/Mitigation Exploitation Wave Incident

F5 BIG-IP APM RCE exploitation and response

Updated 02.04.2026 11:25
Case score 62
Members 4 First seen 15.10.2025 16:32 Latest activity 02.04.2026 11:25

Overview

Attackers are actively exploiting **CVE-2025-53521** against **F5 BIG-IP APM** systems, turning an issue first disclosed as denial of service into unauthenticated remote code execution on exposed appliances. F5 has published fixed releases and compromise-check guidance, while **CISA** has placed the CVE in **KEV** and pushed rapid remediation. An earlier F5 intrusion into BIG-IP development systems adds background because source code and information about undisclosed vulnerabilities were stolen, but available evidence does not show that material being used in the current attacks. Current priority is patching, checking for indicators of compromise, and validating whether exposed BIG-IP APM systems have already been accessed.
Latest development Open development history 4 earlier developments Shadowserver measures BIG-IP APM exposure at internet scale Shadowserver says it now tracks over 17,100 IPs with BIG-IP APM fingerprints and more than 14,000 BIG-IP APM systems remain exposed to CVE-2025-53521 attacks, showing a broad internet-facing exposure base during the ongoing exploitation wave.
  1. Earlier development

    CISA adds CVE-2025-53521 to KEV and orders rapid patching

    CISA added CVE-2025-53521 to the Known Exploited Vulnerabilities catalog and told federal agencies to patch vulnerable F5 BIG-IP systems within three days after confirming exploitation in the wild. F5 said the flaw affects BIG-IP APM deployments with an access policy configured on a virtual server, can permit unauthenticated remote code execution, and published indicators of compromise including rogue files, hash and timestamp mismatches, and suspicious HTTP/S activity.

  2. Earlier development

    F5 learns of breach

    F5 learned of a breach on August 9, 2025 after unidentified threat actors maintained long-term, persistent access to its network and stole files containing some BIG-IP source code and information related to undisclosed vulnerabilities.

  3. Earlier development

    F5 publicly discloses the breach and theft of BIG-IP source code

    On October 15, 2025, F5 publicly disclosed that nation-state hackers breached its systems and stole undisclosed BIG-IP security vulnerabilities and source code. F5 also stated that it had seen no evidence that the attackers used the stolen information in actual attacks, no evidence that the private information was disclosed, no suspicious code modifications, and no material impact to operations.

  4. Earlier development

    F5 detects unauthorized access to BIG-IP systems

    F5 became aware of unauthorized access to its systems on August 9, 2025, and investigators later determined that the threat actor maintained long-term, persistent access to the BIG-IP product development environment and engineering knowledge management platform. Files exfiltrated from those systems included portions of BIG-IP source code, information about undisclosed vulnerabilities, and some customer configuration or implementation details.

Signals

Impact signals
Exploitation
CVEs/products
Geographic context
Remediation
Status
Threat context

Malware & tooling context

1 families · 1 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability F5 BIG-IP APM unauthenticated RCE (CVE-2025-53521)
Updated 30.03.2026 10:07 Lead Contribution 59
Exploitation Active Exploitation Exploit Public Exploit CVSS 9.8 Critical Patch Patch Available

**CVE-2025-53521** is being **actively exploited** against **F5 BIG-IP APM** deployments, creating **unauthenticated remote code execution** risk for exposed systems. The flaw affects BIG-IP APM systems with an **access policy configured on a virtual server**, including **Appliance mode**. F5 says fixed releases are available, and **CISA** has added the CVE to its **Known Exploited Vulnerabilities** list. Organizations should prioritize patching because the weakness has already been abused in the wild.

Exploitation Wave F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Updated 02.04.2026 11:25 Scoring Support Contribution 2
Exploitation Active Exploitation Patch Patch Available

As of **2026-04-02**, ongoing attacks are exploiting **CVE-2025-53521** against **F5 BIG-IP APM** systems, leaving more than **14,000** exposed online and at risk of remote code execution. F5 said the flaw was reclassified from **DoS** to **RCE** after new information in **March 2026**, and **CISA** has added it to its **actively exploited** list. The exploitation wave targets unpatched systems with access policies configured on a virtual server, which makes internet-facing deployments especially risky.

Incident F5 hit by network compromise
Updated 15.10.2025 16:32 Scoring Support Contribution 1
Extortion None Incident Disclosed

F5 disclosed a nation-state intrusion that compromised BIG-IP development systems and related engineering knowledge-management resources. The intrusion was first detected on August 9, 2025 and publicly disclosed on October 15, 2025. Files taken in the incident included portions of BIG-IP source code and information about undisclosed vulnerabilities. Investigators described long-term, persistent access and said the company rotated credentials, strengthened access controls, expanded monitoring, and engaged external responders including Google Mandiant and CrowdStrike. F5 also reported that there was no evidence of malicious exploitation of the vulnerabilities and no new unauthorized activity after containment efforts. Some exfiltrated knowledge-management files may have contained customer configuration or implementation information for a small percentage of customers. The company also said other core systems such as CRM, financial, support case management, and iHealth were not reached.

Advisory/Mitigation CISA KEV patch directive for CVE-2025-53521
Updated 30.03.2026 10:07 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency Immediate Patch Patch Available

CISA added **CVE-2025-53521** to its **KEV catalog** and told **federal agencies** to patch the F5 BIG-IP flaw within **three days**. The directive is urgent because the bug is being **exploited in the wild** and can enable **unauthenticated remote code execution**. F5 says the issue affects **BIG-IP APM** deployments with an access policy configured on a virtual server, and fixed releases are available.