Attackers Exploit RCE Flaw as 14,000 F5 BIG-IP APM Instances Remain Exposed


Attackers Exploit RCE Flaw as 14,000 F5 BIG-IP APM Instances Remain Exposed

Pierluigi Paganini
April 06, 2026

Over 14,000 F5 BIG-IP APM instances remain exposed online, as attackers actively exploit a critical remote code execution flaw CVE-2025-53521.

Over 14,000 F5 BIG-IP APM instances remain exposed online, with attackers actively exploiting the critical remote code execution vulnerability CVE-2025-53521 (CVSS ver. 3.1 score of 9.8), the nonprofit security organization Shadowserver warns.

The vulnerability in BIG-IP APM allows specially crafted malicious traffic to trigger Remote Code Execution (RCE) when an access policy is enabled on a virtual server.

“When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).” reads the advisory. “Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.”

The researchers reported the flaw five months ago, in October. The flaw was previously classified as a Denial-of-Service (DoS) issue, which has been reclassified as a critical Remote Code Execution (RCE) flaw based on new findings in March 2026. Its severity has increased significantly, with higher CVSS scores. The original fix remains effective, but the flaw has been actively exploited in vulnerable BIG-IP versions.

“We have learned that this vulnerability has been exploited in the vulnerable BIG-IP versions below.” reads the vendor’s advisory.

F5 thanks Schuberg Philis, Bart Vrancken, Fox-IT, and the Dutch NCSC for their help in investigating the issue and ensuring a high-standard coordinated disclosure.

Shadowserver now reports tracking over 14,100 IPs with F5 BIG-IP APM fingerprints exposed online, most of them are in the US (5138), Europe (4750), and Asia (2689).

It’s unclear how many are actually vulnerable to exploitation.

At the end of March, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw in F5 BIG-IP AMP to its Known Exploited Vulnerabilities (KEV) catalog.

CISA orders federal agencies to fix the vulnerability by March 30, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Nothing beats an addictive documentary, whether a feature-length film or a multipart docuseries. Netflix has an attractive collection of documentaries, providing so many to choose from that I never run out of options when I need my documentary fix.

In 2026, new documentaries are coming your way, spanning true crime, sports, nature, and more topics. Here are five documentaries that you need to add to your Netflix watch list this year.

The Investigation of Lucy Letby

Netflix always comes through with its collection of true crime titles, and a recent addition is The Investigation of Lucy Letby. The film walks you through how one of the UK’s most disturbing medical crime cases slowly came to light. It traces the investigation into Lucy Letby, a neonatal intensive care nurse in Chester, England, suspected of murdering babies in her care. The film explores how Letby’s crimes, despite her shy and quiet demeanor, are exposed after an investigation by the hospital’s risk management team and police. The documentary also touches upon her trial.

The Investigation of Lucy Letby features first-hand interviews of detectives and witnesses involved in the case, as well as Letby’s attorney and friend.

The Investigation of Lucy Letby is now streaming on Netflix.

Queen of Chess

Queen of Chess is a must-watch docufilm for chess and documentary fans alike. The sports documentary follows the true story of the 12-year-old Hungarian prodigy Judit Polgár, who battled all prejudices against her gender and age to emerge as the number one female chess player at 12, beating Bobby Fischer’s record as the youngest grandmaster of all time at 15.

Premiering at the 2026 Sundance Film Festival, this docufilm also dives into Polgár’s personal journey with love, forging her path while discovering what success truly meant for her.​​​​​​​

Queen of Chess is now streaming on Netflix.

Kidnapped: Elizabeth Smart

Another true-crime documentary you don’t want to miss on Netflix this year is Kidnapped: Elizabeth Smart, a gripping film that premiered in January. It tells the true story of the kidnapping of Elizabeth, who was taken from her bedroom in Utah in 2002 as a young teenager, sparking what remains one of the most widely discussed missing persons cases in the US. Left with little evidence except for a young witness, investigators embark on a rescue mission that lasts over nine months, involving community efforts and confusing suspects.

This gripping documentary gives you detailed coverage of what went down, featuring first-hand accounts from Elizabeth herself, as well as exclusive interviews with her family, investigators, and those closest to the case.

Kidnapped: Elizabeth Smart is now streaming on Netflix.

Miracle: The Boys of ’80

Love sports documentaries? Don’t miss this hockey documentary, Miracle: The Boys of ’80, that offers a nostalgic, behind-the-scenes look at the underdog U.S. men’s hockey team that pulled off one of the greatest upsets in sports history at the 1980 Winter Olympics, emerging as heroes. Told through interviews with the players themselves, the docufilm revisits how a group of young, relatively unknown athletes came together under coach Herb Brooks and shocked the world by defeating the seemingly unbeatable Soviet team.

Miracle: The Boys of ’80 is now streaming on Netflix.

Louis Theroux: Inside The Manosphere

For a docufilm that touches on contemporary social issues, don’t miss out on Louis Theroux: Inside The Manosphere. The film sees Louis Theroux step into the online world of the “manosphere,” a loose network of online forums and communities built around extreme views of masculinity and misogyny. Through probing conversations, Theroux speaks to men as well as influential influencers in this ultra-masculine bubble who blame feminism and society for their frustrations, unpacking how anger, insecurity, and loneliness often fuel extreme ideologies.

Louis Theroux: Inside The Manosphere begins streaming globally on March 11, 2026.


To stay updated on the latest Netflix releases, make sure you enable mobile and desktop notifications. You can also keep an eye on the New and Updated tab to see the newest releases in your region.

Subscription with ads

Yes, $8/month

Simultaneous streams

Two or four

Stream licensed and original programming with a monthly Netflix subscription.




Source link