CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation

CISA has added a critical F5 BIG-IP APM vulnerability (CVE-2025-53521) to its Known Exploited Vulnerabilities catalog following evidence of active exploitation and its reclassification as a remote code execution flaw.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw impacting F5 BIG-IP Access Policy Manager (APM) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in question is CVE-2025-53521 (CVSS v4 score: 9.3), which could allow a threat actor to achieve remote code execution. While the shortcoming was initially categorized and remediated as a denial-of-service (DoS) vulnerability with a CVSS v4 score of 8.7, F5 said it has been reclassified as a case of RCE in light of new information obtained in March 2026. The company has since updated its advisory to confirm that the vulnerability has been exploited in the vulnerable BIG-IP versions. F5 published a number of indicators that can be used to assess if the system has been compromised, including file-related indicators, log-related indicators, and other observed TTPs such as in-memory webshells and disguised HTTP traffic. The issue impacts versions 17.5, 17.1, 16.1, and 15.1. Federal agencies have been given until March 30, 2026, to apply the fixes. Security experts have noted acute scanning activity for vulnerable devices following the CISA announcement.
Source: The Hacker News
















