CVE-2025-53521

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • Published Oct 15, 2025
  • CVSS 9.3 critical
  • 2.3% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog

Affected software

In the news

CVE-2025-53521 at the National Vulnerability Database