Junglewise Threat Intelligence

CVE-2025-53521: F5 BIG-IP stack-based buffer overflow in APM

CVE-2025-53521 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-03-27

Technologies: F5 Big-Ip Access Policy Manager, F5 BIG-IP. Vendors: F5.

Executive brief

F5 BIG-IP Access Policy Manager (APM), a solution used to manage secure remote access to corporate applications, contains a critical security flaw. An unauthenticated attacker can exploit this vulnerability by sending malicious network traffic to a virtual server, potentially taking full control of the system. This vulnerability is known to be actively exploited in the wild, posing a significant risk to organizational data and network integrity.

Technical details

A stack-based buffer overflow (CWE-121) exists in F5 BIG-IP when an Access Policy Manager (APM) policy is configured on a virtual server. The vulnerability is triggered by processing specific malicious network traffic, allowing an unauthenticated remote attacker to execute arbitrary code with high privileges. This flaw has been observed in active exploitation. Patches are available in versions 15.1.10.8, 16.1.6.1, 17.1.3, and 17.5.1.3; users are advised to update immediately or apply vendor-recommended mitigations.

Affected products

  • F5 BIG-IP Access Policy Manager (APM) 15.1.0 to 15.1.10.7, 16.1.0 to 16.1.6.0, 17.1.0 to 17.1.2, 17.5.0 to 17.5.1.2

Timeline

  • 2026-03-27: advisory: Initial publication and CISA KEV addition
  • 2026-03-27: exploited: Confirmed active exploitation in the wild

Related threats