F5 BIG-IP APM RCE exploitation and response
Case score 62
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 62
- Main story score
- 59
- Related evidence lift
- +3 / 20
- Contributing updates
- 2
- Context updates
- 1
- Vulnerability Defines the exploited flaw, affected product, and fixed-release scope. main
- Advisory Mitigation Provides CISA KEV and patch-deadline context for the same vulnerability. context
- Exploitation Wave Adds active exploitation evidence and large exposed-system measurements. contributes
- Incident Adds background on an earlier F5 BIG-IP intrusion and source-code theft. contributes
Overview
Latest development Open development history Shadowserver measures BIG-IP APM exposure at internet scale Shadowserver says it now tracks over 17,100 IPs with BIG-IP APM fingerprints and more than 14,000 BIG-IP APM systems remain exposed to CVE-2025-53521 attacks, showing a broad internet-facing exposure base during the ongoing exploitation wave.
-
CISA adds CVE-2025-53521 to KEV and orders rapid patching
CISA added CVE-2025-53521 to the Known Exploited Vulnerabilities catalog and told federal agencies to patch vulnerable F5 BIG-IP systems within three days after confirming exploitation in the wild. F5 said the flaw affects BIG-IP APM deployments with an access policy configured on a virtual server, can permit unauthenticated remote code execution, and published indicators of compromise including rogue files, hash and timestamp mismatches, and suspicious HTTP/S activity.
-
F5 learns of breach
F5 learned of a breach on August 9, 2025 after unidentified threat actors maintained long-term, persistent access to its network and stole files containing some BIG-IP source code and information related to undisclosed vulnerabilities.
-
F5 publicly discloses the breach and theft of BIG-IP source code
On October 15, 2025, F5 publicly disclosed that nation-state hackers breached its systems and stole undisclosed BIG-IP security vulnerabilities and source code. F5 also stated that it had seen no evidence that the attackers used the stolen information in actual attacks, no evidence that the private information was disclosed, no suspicious code modifications, and no material impact to operations.
-
F5 detects unauthorized access to BIG-IP systems
F5 became aware of unauthorized access to its systems on August 9, 2025, and investigators later determined that the threat actor maintained long-term, persistent access to the BIG-IP product development environment and engineering knowledge management platform. Files exfiltrated from those systems included portions of BIG-IP source code, information about undisclosed vulnerabilities, and some customer configuration or implementation details.