ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Attackers are exploiting RCE vulnerability in BIG-IP APM systems (CVE-2025-53521)

criticalVulnerability exploited in the wildimportance 60CVE-2025-53521

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-53521
Stack-Based Buffer Overflow in F5 BIG-IP APM Enables Unauthenticated RCE

CVE-2025-53521 is a stack-based buffer overflow (CWE-121) in F5 BIG-IP's Access Policy Manager (APM) that allows remote code execution. The flaw is triggered when a virtual server is configured with an APM access policy and receives specific malicious network traffic; no authentication or user interaction is required per the CVSS 4.0 vector. An attacker who exploits it gains remote code execution on the BIG-IP device, and in observed intrusions attackers have deployed a fileless Linux rootkit (dubbed 'PoisonedRefresh') that injects a PHP web shell into server memory to evade disk-based scanning. Any F5 BIG-IP deployment with an APM access policy configured on a virtual server is potentially affected; versions that have reached End of Technical Support are not evaluated by the vendor. The vulnerability is being actively exploited in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-27, with active exploitation and in-memory malware campaigns confirmed in press reports, though ransomware use is unknown.

Do: Patch immediately by upgrading affected BIG-IP systems to fixed releases per F5's security advisory (note that versions in End of Technical Support will not be fixed and should be upgraded or retired), prioritizing internet-facing virtual servers with APM access policies. Because observed attacks deploy a memory-resident PHP web shell via the PoisonedRefresh Linux rootkit, disk-only scans may miss compromise — inspect running processes and memory, and hunt for suspicious PHP or rootkit activity on BIG-IP APM devices. Federal agencies must follow the required action in CISA KEV/BOD 22-01: apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

9.32% KEV
  • F5 BIG-IP (BIG-IP Access Policy Manager / APM)
large≈14,000+ internet-exposed F5 BIG-IP devices (per public scan figures cited in press coverage)
Full article565 words · extracted from helpnetsecurity.com · click to collapse

A critical unauthenticated remote code execution vulnerability (CVE-2025-53521) in F5’s BIG-IP Access Policy Manager (APM) solution is under active exploitation, the US Cybersecurity and Infrastructure Security Agency warned on Friday.

BIG-IP CVE-2025-53521 exploited

CISA added the flaw to its Known Exploited Vulnerabilities catalog after F5 updated the related security advisory,

The advisory was initially published on October 15, 2025, when F5 confirmed a data breach that resulted in a “highly sophisticated nation-state threat actor” accessing – among other things – BIG-IP source code and information about undisclosed vulnerabilities.

It was later revealed that the attackers are linked to China, were in the company’s network for at least 12 months, and may have deployed the Brickstorm backdoor on F5 customers’ systems.

About CVE-2025-53521

F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data. It’s primarely used by enterprises, financial institutions, and government and public sector organizations.

CVE-2025-53521 affects the apmd process – which processes live traffic – in BIG-IP APM versions 17.5.0 to 17.5.1, 17.1.0 to 17.1.2, 16.1.0 to 16.1.6, and 15.1.0 to 15.1.10.

It was initially believed that CVE-2025-53521 could only lead to a disruption of the normal functioning of BIG-IP APM systems (i.e., “denial of service”).

“Due to new information obtained in March 2026, the original vulnerability is being re-categorized to an RCE with CVSS scores of 9.8 (CVSS v3.1) and 9.3 (CVSS v4.0),” F5 now says.

“When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to remote code execution. The BIG-IP system in Appliance mode is also vulnerable.”

The patches provided by the company in October 2025 work as intended, though, and customers who have quickly updated to one of the fixed versions might have avoided compromise.

Indicators of compromise are available

Unfortunately, the advisory does not say when the exploitation of the flaw began, only that it was discovered in March 2026. It’s possible, then, that some of the BIG-IP APM systems out there might have been compromised before they were patched.

F5 has published a list of known indicators of compromise associated with “malicious software c05d5254” and related activity, and is urging customers to check their BIG-IP systems.

Customers may discover specific files on disk, changes to files, log entries that point to a local user disabling the SELinux security module, and specific HTTP/S traffic from the BIG-IP system.

“We have observed cases of webshell being written to disk; however, the webshells have been observed to work in memory only, meaning the files listed [in the document] might not be modified,” the company noted.

F5 has also detected the threat actor making modifications that would affect the functioning of sys-eicheck, the BIG-IP system integrity checker.

“Our understanding at this time is that the threat actor modified [specific] components in one partition (original running version compromised) but failed to make the same modifications on the second partition (destination for upgrade). When the customer upgraded and rebooted into the second partition, the modifications to sys-eicheck components did not persist.”

CISA has ordered US federal civilian agencies to assess exposure and mitigate risks related to CVE-2025-53521 exploitation by Monday (March 30).

UPDATE (March 30, 2026, 06:15 a.m. ET):

The Dutch National Cyber Security Center “has observed that this vulnerability has been abused.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/03/28/big-ip-apm-vulnerability-cve-2025-53521-exploited/