Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Mar 30, 2026

CVE-2025-53521

High
EPSS 19.2%CISA KEV
F5/BIG-IP

Description

F5 BIG-IP APM contains an unspecified vulnerability that could allow a threat actor to achieve remote code execution.

EPSS — Exploit Probability

19.2%

Higher than 95.3% of all CVEs

Required Action

Please adhere to F5’s guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible F5 products affected by this vulnerability. For more information please see: https://my.f5.com/manage/s/article/K000156741 ; https://my.f5.com/manage/s/article/K000160486 ; https://my.f5.com/manage/s/article/K11438344 ; https://nvd.nist.gov/vuln/detail/CVE-2025-53521

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
19.2%
CISA KEV
Yes
Ransomware
Unknown
Articles
2

Timeline

Published

Mar 27, 2026

Added to KEV

Mar 27, 2026

Remediation Due

Mar 30, 2026

Affected Product

F5

BIG-IP

View all F5 CVEs