← Vulnerability feed

Vulnerability record · CVE-2025-53521 · published 15 October 2025

CVE-2025-53521: F5 BIG-IP APM stack buffer overflow allows remote code execution

F5 · Big Ip Access Policy Manager

A stack-based buffer overflow (CWE-121) exists in F5 BIG-IP Access Policy Manager when an APM access policy is configured on a virtual server. Specific malicious traffic can trigger remote code execution, and the flaw is rated critical with a CVSS 4.0 score of 9.3.

9.3 CVSS 4.0 Critical CISA KEV since 27 Mar 2026 EPSS 2.3% · top 17.4% CWE-121 · Stack-based buffer overflow
9.3CVSS 4.0 base score
2.3%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 4.0 score of 9.3, unauthenticated network-reachable RCE, and confirmed inclusion in CISA KEV make this an urgent patching priority.

What it is

A stack-based buffer overflow (CWE-121) exists in F5 BIG-IP Access Policy Manager when an APM access policy is configured on a virtual server. Specific malicious traffic can trigger remote code execution, and the flaw is rated critical with a CVSS 4.0 score of 9.3.

Impact

An unauthenticated remote attacker can execute arbitrary code on the affected BIG-IP system, potentially gaining full control of the device and any traffic or credentials it brokers.

Attack surface

Reachable over the network via the virtual server hosting the APM access policy; the CVSS vector indicates no privileges and no user interaction are required.

Exploitation

CVE-2025-53521 is listed in CISA's Known Exploited Vulnerabilities catalog with a 2026-03-30 remediation due date, confirming active exploitation; EPSS 30-day probability is about 2.3 percent (82nd percentile).

What to do

  • Apply the F5 vendor patch or fixed version per advisory K000156741 as the first action.
  • If patching is not immediately possible, apply F5's documented mitigations or disable the APM access policy on affected virtual servers.
  • Follow BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable.
  • Restrict network access to BIG-IP management and virtual server interfaces to trusted sources where feasible.
  • Verify no end-of-technical-support BIG-IP versions remain in service, as they are not evaluated for this flaw.

Detection

  • Monitor BIG-IP logs and APM access policy events for crashes, restarts or abnormal process termination on virtual servers.
  • Inspect network traffic to APM-enabled virtual servers for malformed or unusually large requests consistent with buffer overflow attempts.
  • Alert on unexpected child processes, shell activity or outbound connections originating from the BIG-IP device.
  • Review F5 and CISA advisories for indicators and update detection content as vendor guidance evolves.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-53521 to the Known Exploited Vulnerabilities catalog on 27 March 2026 as "F5 BIG-IP Stack-Based Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 30 March 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-53521 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46747F5 BIG-IP configuration utility authentication bypass allows command executionUndisclosed requests can bypass authentication in the BIG-IP configuration utility, letting a network-positioned attacker execute arbitrary system co…KEVEPSS 97%analysed9.8CVE-2022-1388F5 BIG-IP iControl REST authentication bypassUndisclosed requests to the iControl REST interface on multiple F5 BIG-IP modules can bypass authentication, allowing an unauthenticated remote attac…KEVEPSS 100%analysed9.8CVE-2021-22991F5 BIG-IP TMM URI normalization buffer overflowF5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overf…KEVEPSS 61%analysed9.8CVE-2021-22986F5 BIG-IP iControl REST unauthenticated remote command executionThe iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 se…KEVEPSS 100%analysed9.8CVE-2020-5902F5 BIG-IP TMUI path traversal leading to remote code executionThe F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed …KEVEPSS 100%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.3CVE-2026-94127F5 big-ip access policy manager heap-based buffer overflow vulnerabilityWhen a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution…KEVEPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2025-53521), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.