Vulnerability record · CVE-2025-53521 · published 15 October 2025
CVE-2025-53521: F5 BIG-IP APM stack buffer overflow allows remote code execution
F5 · Big Ip Access Policy Manager
A stack-based buffer overflow (CWE-121) exists in F5 BIG-IP Access Policy Manager when an APM access policy is configured on a virtual server. Specific malicious traffic can trigger remote code execution, and the flaw is rated critical with a CVSS 4.0 score of 9.3.
Description
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 4.0 score of 9.3, unauthenticated network-reachable RCE, and confirmed inclusion in CISA KEV make this an urgent patching priority.
What it is
A stack-based buffer overflow (CWE-121) exists in F5 BIG-IP Access Policy Manager when an APM access policy is configured on a virtual server. Specific malicious traffic can trigger remote code execution, and the flaw is rated critical with a CVSS 4.0 score of 9.3.
Impact
An unauthenticated remote attacker can execute arbitrary code on the affected BIG-IP system, potentially gaining full control of the device and any traffic or credentials it brokers.
Attack surface
Reachable over the network via the virtual server hosting the APM access policy; the CVSS vector indicates no privileges and no user interaction are required.
Exploitation
CVE-2025-53521 is listed in CISA's Known Exploited Vulnerabilities catalog with a 2026-03-30 remediation due date, confirming active exploitation; EPSS 30-day probability is about 2.3 percent (82nd percentile).
What to do
- Apply the F5 vendor patch or fixed version per advisory K000156741 as the first action.
- If patching is not immediately possible, apply F5's documented mitigations or disable the APM access policy on affected virtual servers.
- Follow BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable.
- Restrict network access to BIG-IP management and virtual server interfaces to trusted sources where feasible.
- Verify no end-of-technical-support BIG-IP versions remain in service, as they are not evaluated for this flaw.
Detection
- Monitor BIG-IP logs and APM access policy events for crashes, restarts or abnormal process termination on virtual servers.
- Inspect network traffic to APM-enabled virtual servers for malformed or unusually large requests consistent with buffer overflow attempts.
- Alert on unexpected child processes, shell activity or outbound connections originating from the BIG-IP device.
- Review F5 and CISA advisories for indicators and update detection content as vendor guidance evolves.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-53521 to the Known Exploited Vulnerabilities catalog on 27 March 2026 as "F5 BIG-IP Stack-Based Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 30 March 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://my.f5.com/manage/s/article/K000156741 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-53521 | US Government Resource |
Track CVE-2025-53521 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-53521), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.