On October 15, 2025, F5 published the vulnerability CVE-2025-53521 in BIG-IP Access Policy Manager (APM) as part of the quarterly notification (K000156572) – at the time classified as a denial of service. In March 2026, the flaw was reassessed: it is in fact a remote code execution exploitable without authentication (pre-auth RCE), according to F5 with a CVSS v4 score of 9.3. Since then it has been actively exploited. Attack chains documented in press reports include code execution via the APM service, the subsequent abuse of the iControl REST interface, and the deposit of – predominantly memory-resident – web shells on compromised devices.
The US agency CISA added the vulnerability to the KEV catalog of actively exploited vulnerabilities on March 27, 2026, and set US federal agencies a deadline until March 30 – three days, an unusually tight window that underscores the urgency. This BOD deadline has meanwhile already passed; for companies outside the federal-agency scope, the pressure to act remains just as high. The BSI warns with notice 2026-238368-1032. Given the large number of internet-reachable BIG-IP systems, a broad attack surface must be assumed.
For context: in October 2025, F5 acknowledged a breach of its own development environment in which source code and information on undisclosed vulnerabilities were exfiltrated. The current exploitation of a flaw initially rated harmless is exactly the materialization of the risk that has been warned about ever since: attackers who know F5 internals can assess vulnerabilities faster and more deeply than the public state of knowledge.
Who is affected
Affected are BIG-IP systems of the version branches 15.1 to 17.5 on which the APM module is in use – typically for SSL VPN, remote access, and single sign-on, that is, precisely the systems that are, by design, reachable from the internet. F5 provides fixed versions: 17.5.1.3, 17.1.3, 16.1.6.1, and 15.1.10.8.
If you are not sure whether APM is provisioned on your BIG-IPs or which access policies are exposed, that is exactly the first question you should clarify today.
What to do now
- Patch immediately to 17.5.1.3, 17.1.3, 16.1.6.1, or 15.1.10.8 – the flaw is being actively exploited, and a regular maintenance window is the wrong category here.
- Do not expect a workaround: According to the BSI, there is no effective interim solution. Anyone who cannot patch immediately should suppress the reachability of affected APM portals as far as possible and treat the system as at risk until the update.
- Reduce exposure: Management interfaces fundamentally do not belong on the internet; make APM portals reachable only as far as the use case strictly requires.
- Check for compromise, don’t just patch: F5 provides guidance for checking for indicators of compromise with K000160486. Since the observed web shells work predominantly memory-resident, a look at the file system is not enough – every exposed asset left unpatched for a longer time is to be treated as potentially compromised.
- On a finding: Start the incident response process, take a forensic image of the device, and rotate certificates and credentials stored on it.
How sector7 helps
As an owner-led systems integrator with F5 certification, we take over the assessment, patch planning, and compromise check of your BIG-IP environment – at short notice too. Our 24/7 NOC monitoring detects anomalies on network and security infrastructure before they turn into an incident. All of this at flat monthly rates, as a predictable managed service.
Sources
- F5, Quarterly Security Notification K000156572: https://my.f5.com/manage/s/article/K000156572
- F5, Advisory for CVE-2025-53521 (K000156741): https://my.f5.com/manage/s/article/K000156741
- BSI cybersecurity warning 2026-238368-1032: https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-238368-1032.pdf
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- The Hacker News (2026-03-28): https://thehackernews.com/2026/03/cisa-adds-cve-2025-53521-to-kev-after.html
- BleepingComputer (2026-03-30): https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-f5-big-ip-flaw-in-attacks-patch-now/