CVE-2025-53521 – F5 BIG-IP

CVSS 9.8 CRITICAL

“One exposed endpoint can hand over the entire system.”

This patch addresses a critical remote code execution vulnerability in F5 BIG-IP tracked as CVE-2025-53521. The issue allows attackers to execute arbitrary code on affected systems, creating immediate risk of full system compromise, data exposure, and service disruption. The CVSS score is 9.8, which is Critical severity.

Active exploitation has been confirmed, significantly increasing the urgency for remediation. Systems exposed to untrusted networks are especially at risk, as attackers can leverage this vulnerability with little to no authentication. This patch closes the attack path and is essential for maintaining system integrity and availability.

Key Details

Affected Product
F5 Big-ip Access Policy Manager
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-121
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.