Critical Vulnerability Exposes BIG-IP Systems to Remote Code Execution Attacks
A serious security flaw in F5 Networks’ BIG-IP Access Policy Manager (APM) has been reclassified as a critical remote code execution (RCE) vulnerability. Identified as CVE-2025-53521, this issue allows attackers to exploit unpatched systems and deploy malicious webshells.
The vulnerability affects numerous organizations using BIG-IP APM, which is designed to manage user access to networks and applications. Currently, over 240,000 instances are exposed online, raising concerns about potential exploitation.
The impact of this attack could lead to unauthorized access, data breaches, and severe disruptions for affected businesses. F5 Networks has urged organizations to review their security policies and check for signs of compromise.
To protect against this threat, it’s essential to apply vendor-recommended mitigations and regularly update systems. Given the potential for significant damage, the risk level for this vulnerability is assessed as High.
Source: View Original Report
