ESET Research[verified]@ESETresearchActive Exploitation
Researchers identified the PoisonedRefresh malware targeting F5 BIG‑IP devices via CVE‑2025‑53521, demonstrating that the vulnerability is being actively exploited in the wild.
FOFA[verified]@fofabotActive Exploitation
The tweet announces that CVE-2025‑53521, a high‑severity unauthenticated RCE in F5 BIG‑IP APM, is actively exploited in the wild to deploy a memory‑only Linux rootkit on SSL‑VPN appliances.
إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediActive Exploitation
The text confirms that CVE‑2025‑53521 is actively exploited (KEV), highlights its RCE nature and critical score, and urges immediate patching of F5 BIG‑IP devices.
Simo[verified]@SimoKohonenGeneral
The tweet simply references CVE‑2025‑53521 as an F5 Big‑IP remote code execution vulnerability and notes someone attempting to ping webshells, but provides no further details, PoC, exploit, or patch information.
piyokango[verified]@piyokangoActive Exploitation
CISA confirmed that F5 BIG‑IP CVE‑2025‑53521 is actively exploited; no proof of concept or exploit code is detailed, but technical and impact information is provided.
MigawariIV[verified]@strinsert1NaDisclosure
JPCERT’s notice indicates that CVE‑2025‑53521 in F5 BIG‑IP Access Policy Manager has been re‑classified from a denial‑of‑service flaw to an unauthenticated remote code execution vulnerability, with no exploit, PoC, or active abuse reported.
The Cyber Security Hub™[verified]@TheCyberSecHubActive Exploitation
Attackers are actively exploiting CVE‑2025‑53521, an RCE vulnerability in BIG‑IP APM systems, with no patch or mitigation details provided.
Mr.Rabbit[verified]@01ra66itActive Exploitation
CISA added CVE-2025-53521 to KEV after confirming active exploitation, urging timely patching.