CVE-2025-53521Active Exploitation(f5 / big-ip_access_policy_manager)

CRITICALCVSS 9.3 · CRITICALCISA KEV

Exploitation observed; activity peaked at 58 mentions and remains active

Immediate actions

  • Patch f5 big-ip_access_policy_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-30. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Vendor / third-party advisories
Weakness type (CWE)
CWE-121

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • big-ip_access_policy_manager

Threat summary

  • Active exploitation appears in 211 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 256 mentions across 30 observed days

What's happening

  • Active exploitation reported across 211 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 92 signals
  • Technical details provided in 172 signals
  • General: 19 classified signals
  • Peaked 28d ago at 58 mentions (2026-03-28); latest day: 1
  • 256 total mentions across 30 days

Affected systems

Vendors
Products
big-ip_access_policy_manager

Deep dive

Activity timeline256 mentions / 30d
015294458Mentions · 2026-03-27: 7Mentions · 2026-03-28: 58Mentions · 2026-03-29: 19Mentions · 2026-03-30: 47Mentions · 2026-03-31: 24Mentions · 2026-04-01: 18Mentions · 2026-04-02: 9Mentions · 2026-04-03: 11Mentions · 2026-04-04: 1Mentions · 2026-04-05: 1Mentions · 2026-04-06: 14Mentions · 2026-04-07: 2Mentions · 2026-04-08: 2Mentions · 2026-04-10: 3Mentions · 2026-04-14: 1Mentions · 2026-04-15: 5Mentions · 2026-04-17: 1Mentions · 2026-04-21: 1Mentions · 2026-04-24: 1Mentions · 2026-05-23: 1Mentions · 2026-06-11: 1Mentions · 2026-08-14: 2Mentions · 2026-09-07: 3Mentions · 2026-09-08: 5Mentions · 2026-09-09: 8Mentions · 2026-09-10: 6Mentions · 2026-09-11: 2Mentions · 2026-09-14: 1Mentions · 2026-09-23: 1Mentions · 2026-09-24: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-03-28: 2PoC Mentioned / Linked · 2026-03-29: 1PoC Mentioned / Linked · 2026-04-01: 2PoC Mentioned / Linked · 2026-04-03: 1PoC Mentioned / Linked · 2026-09-07: 1PoC Mentioned / Linked · 2026-09-09: 1PoC Mentioned / Linked · 2026-09-10: 1Exploit Tool / Code · 2026-03-29: 1Exploit Tool / Code · 2026-09-07: 1Exploit Tool / Code · 2026-09-08: 1Exploit Tool / Code · 2026-09-09: 2Exploit Tool / Code · 2026-09-10: 1Active Exploitation · 2026-03-27: 2Active Exploitation · 2026-03-28: 55Active Exploitation · 2026-03-29: 18Active Exploitation · 2026-03-30: 36Active Exploitation · 2026-03-31: 19Active Exploitation · 2026-04-01: 13Active Exploitation · 2026-04-02: 8Active Exploitation · 2026-04-03: 10Active Exploitation · 2026-04-04: 1Active Exploitation · 2026-04-05: 1Active Exploitation · 2026-04-06: 14Active Exploitation · 2026-04-07: 2Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-10: 3Active Exploitation · 2026-04-15: 2Active Exploitation · 2026-04-21: 1Active Exploitation · 2026-04-24: 1Active Exploitation · 2026-05-23: 1Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-08-14: 1Active Exploitation · 2026-09-07: 1Active Exploitation · 2026-09-08: 4Active Exploitation · 2026-09-09: 6Active Exploitation · 2026-09-10: 6Active Exploitation · 2026-09-11: 1Active Exploitation · 2026-09-14: 1Active Exploitation · 2026-09-23: 1Active Exploitation · 2026-09-24: 1Patch / Workaround · 2026-03-27: 3Patch / Workaround · 2026-03-28: 20Patch / Workaround · 2026-03-29: 7Patch / Workaround · 2026-03-30: 11Patch / Workaround · 2026-03-31: 12Patch / Workaround · 2026-04-01: 8Patch / Workaround · 2026-04-02: 5Patch / Workaround · 2026-04-03: 7Patch / Workaround · 2026-04-04: 1Patch / Workaround · 2026-04-06: 5Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-08-14: 1Patch / Workaround · 2026-09-07: 1Patch / Workaround · 2026-09-08: 1Patch / Workaround · 2026-09-09: 2Patch / Workaround · 2026-09-10: 2Patch / Workaround · 2026-09-24: 1Technical Details · 2026-03-27: 7Technical Details · 2026-03-28: 31Technical Details · 2026-03-29: 6Technical Details · 2026-03-30: 32Technical Details · 2026-03-31: 16Technical Details · 2026-04-01: 16Technical Details · 2026-04-02: 9Technical Details · 2026-04-03: 10Technical Details · 2026-04-04: 1Technical Details · 2026-04-05: 1Technical Details · 2026-04-06: 14Technical Details · 2026-04-07: 2Technical Details · 2026-04-08: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-15: 2Technical Details · 2026-04-21: 1Technical Details · 2026-08-14: 1Technical Details · 2026-09-07: 2Technical Details · 2026-09-08: 3Technical Details · 2026-09-09: 7Technical Details · 2026-09-10: 4Technical Details · 2026-09-11: 2Technical Details · 2026-09-14: 1Technical Details · 2026-09-23: 1Technical Details · 2026-09-24: 103-2703-3004-0204-0504-0804-1504-2408-1409-0909-1409-24
Signal classification5 categories
Active Exploitation
20780.9%
General
197.4%
Patch
187.0%
Disclosure
114.3%
Exploit
10.4%
Referenced assets148 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-277
Active Exploitation2Disclosure3General1Patch1
2026-03-2858
Active Exploitation54Disclosure1General1Patch2
2026-03-2919
Active Exploitation18General1
2026-03-3047
Active Exploitation34Disclosure3General7Patch3
2026-03-3124
Active Exploitation18General3Patch3
2026-04-0118
Active Exploitation13Disclosure1General1Patch3
2026-04-029
Active Exploitation8Patch1
2026-04-0311
Active Exploitation10Patch1
2026-04-041
Active Exploitation1
2026-04-051
Active Exploitation1
2026-04-0614
Active Exploitation14
2026-04-072
Active Exploitation2
2026-04-082
Active Exploitation1Disclosure1
2026-04-103
Active Exploitation3
2026-04-141
Patch1
2026-04-155
Active Exploitation2General2Patch1
2026-04-171
Patch1
2026-04-211
Active Exploitation1
2026-04-241
Active Exploitation1
2026-05-231
Active Exploitation1
2026-06-111
Active Exploitation1
2026-08-142
Active Exploitation1General1
2026-09-073
Active Exploitation1Exploit1Patch1
2026-09-085
Active Exploitation4Disclosure1
2026-09-098
Active Exploitation6Disclosure1General1
2026-09-106
Active Exploitation6
2026-09-112
Active Exploitation1General1
2026-09-141
Active Exploitation1
2026-09-231
Active Exploitation1
2026-09-241
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ CISA flagged active exploitation of an F5 BIG-IP APM flaw.CVE-2025-53521 (CVSS 9.3) enables RCE, reclassified from DoS after new findings. Exploitation is confirmed in the wild, with a federal patch deadline set. 🔗 Read → https://thehackernews.com/2026/03/cisa-adds-cve-2025-53521-to-kev-after.html

    Post summary

    The post confirms that CVE-2025-53521 is actively exploited in the wild, has been escalated to a high severity with RCE, and a federal patch deadline has been set.

    24421081613.5K
    1.1M followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    ⚠️We are observing acute scanning activity for F5 BIG-IP following the inclusion of CVE-2025-53521 in CISA KEV This actor is hitting /mgmt/shared/identified-devices/config/device-info which is a F5 BIG-IP REST API endpoint used to retrieve system-level information, such as hostname, machine ID, and base MAC address. Additional IOCs include the user agent "CVE-2025-53521-Scanner/1.0" Track live F5 BIG-IP exploitation on Defused 👉https://console.defusedycyber.com/intel

    Post summary

    Observations indicate that F5 BIG‑IP devices are being scanned and exploited for CVE‑2025‑53521 in the wild, with live monitoring available via Defused.

    4252813820.8K
    6.7K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added F5 BIG-IP remote code execution vulnerability CVE-2025-53521 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/ZrHfYs8fQ7

    Post summary

    The tweet indicates that CVE-2025-53521, a remote code execution flaw in F5 BIG‑IP, is part of the DHS Known Exploited Vulnerabilities Catalog, signifying it has been actively exploited, but no PoC, exploit tool, or patch information is provided.

    322255139.1K
    293.4K followersView on X
  • ESET Research@ESETresearch
    Active Exploitation

    Approximately a month ago, F5 published advisory on malware deployed to BIG-IP systems vulnerable to CVE-2025-53521. #ESETresearch discovered two related malware components on VirusTotal and named the threat #PoisonedRefresh. 1/6 https://my.f5.com/manage/s/article/K000160486

    Post summary

    Researchers identified the PoisonedRefresh malware targeting F5 BIG‑IP devices via CVE‑2025‑53521, demonstrating that the vulnerability is being actively exploited in the wild.

    212142176.4K
    35.9K followersView on X
  • FOFA@fofabot
    Active Exploitation

    ⚠️⚠️ CVE-2025-53521 (CVSS 9.8): Unauthenticated RCE in F5 BIG-IP APM (apmd) — now being exploited to drop the PoisonedRefresh memory-only Linux rootkit on SSL-VPN appliances. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJmNS1CSUdJUCI= 🎯1.6M+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="f5-BIGIP" 🔖Refer: https://www.helpnetsecurity.com/2026/09/09/f5-big-ip-apm-rootkit-hides-web-shell-in-memory #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The tweet announces that CVE-2025‑53521, a high‑severity unauthenticated RCE in F5 BIG‑IP APM, is actively exploited in the wild to deploy a memory‑only Linux rootkit on SSL‑VPN appliances.

    013035173.9K
    14.8K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    🔴ثغره خطيره تستغل في F5 BIG-IP ـ CISA أضافت ثغرة (CVE-2025-53521) لقائمة الثغرات المستغلة فعلياً (KEV) بعد ما تأكدوا إن فيه استغلال نشط للثغره من قبل المخترقين. 🔵وش هي قائمه KEV؟ هذي القائمة للثغرات اللي الهكرز جالسين يستخدمونها في هجماتهم "اليوم". ـ CISA ما تحط أي ثغرة فيها إلا لو شافت أدلة قاطعة إن فيه شركات تضررت فعلاً 📍 التفاصيل التقنية: 🔴 الثغرة من نوع (RCE)؛ يعني الهكر يقدر يشغل كود خبيث عن بعد. 🔴تصنيفها 9.3 CRITICAL 🔵حدّث نظام F5 BIG-IP لآخر إصدار "فوراً". 🔵راجع تفاصيل CVE-2025-53521 في موقع F5 الرسمي. 🔵افحص الـ (Logs) وابحث عن أي أنماط غريبة.

    Post summary

    The text confirms that CVE‑2025‑53521 is actively exploited (KEV), highlights its RCE nature and critical score, and urges immediate patching of F5 BIG‑IP devices.

    14027163.5K
    49.2K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    CISA adds F5 BIG-IP RCE (CVE-2025-53521) to its KEV Catalog. With a 9.8 CVSS score and active exploits, federal agencies must patch by March 30, 2026. #F5 #BIGIP #CyberSecurity #InfoSec #RCE #CISA #PatchAlert #Vulnerability #NetworkSecurity #CVE https://securityonline.info/f5-big-ip-rce-vulnerability-cve-2025-53521-cisa-kev/ https://t.co/6dVwJa7fgM

    Post summary

    CISA has added F5 BIG‑IP RCE (CVE‑2025‑53521) to its KEV catalog, noting a 9.8 CVSS score, active exploitation, and urging federal agencies to patch by March 30, 2026.

    0612271.8K
    11.0K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    F5 BIG-IP APM CVE-2025-53521 impact has recently been updated from a DoS to RCE (see: https://my.f5.com/manage/s/article/K000156741) & added to @CISACyber KEV. We are fingerprinting & sharing F5 BIG-IP APM instances - over 17.1K IPs seen on 2026-03-31 globally. This is just a population assessment. https://t.co/MrkBlAgUxC

    Post summary

    CVE-2025-53521 for F5 BIG-IP APM now classified as an RCE and listed in the CISACyber KEV, indicating active exploitation in the wild, with a large population assessment of affected IPs.

    2911853.7K
    21.8K followersView on X
  • Simo@SimoKohonen
    General

    Hmm... someone trying to ping their CVE-2025-53521 webshells? (the recently upgraded F5 Big-IP RCE) Unfortunately "BSOHAzPB" doesn't return anything else from our entire dataset https://t.co/ku2rUQDv3v

    Post summary

    The tweet simply references CVE‑2025‑53521 as an F5 Big‑IP remote code execution vulnerability and notes someone attempting to ping webshells, but provides no further details, PoC, exploit, or patch information.

    23020104.1K
    3.2K followersView on X
  • The Shadowserver Foundation@Shadowserver
    General

    We are scanning & reporting F5 BIG-IP APM CVE-2025-53521 instances thanks to collaboration with the @ncsc_nl SRT. 10 months after vuln disclosure, we still see over 850 IPs vulnerable to potential RCE. Top affected: US with 199 & Japan 182. IP data in Vulnerable HTTP reporting. https://t.co/LiHmTY1sw6

    Post summary

    The tweet reports ongoing scans of F5 BIG‑IP APM instances affected by CVE‑2025‑53521, noting over 850 vulnerable IPs and indicating a potential remote code execution weakness.

    2711163.4K
    22.0K followersView on X
  • Hackread.com@HackRead
    Active Exploitation

    F5 BIG-IP APM vulnerability (CVE-2025-53521) escalates to critical 9.8 RCE, actively exploited. Patch now, check IoCs, and secure vulnerable systems immediately. Read: https://hackread.com/critical-f5-big-ip-flaw-upgrad-to-9-8-rce-exploited/ #CyberSecurity #F5 #Vulnerability #DDoS #RCE

    Post summary

    CVE‑2025‑53521 is a critical RCE in F5 BIG‑IP APM with a CVSS score of 9.8, is being actively exploited, and has an available patch—immediate remediation is advised.

    1411151.4K
    114.2K followersView on X
  • CERT-FR@CERT_FR
    Active Exploitation

    ⚠️ Alerte CERT-FR ⚠️ La vulnérabilité CVE-2025-53521 est activement exploitée et permet de provoquer une exécution de code arbitraire à distance dans F5 Big-IP APM. https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-004/

    Post summary

    The alert reports that CVE‑2025‑53521 is actively exploited to achieve remote code execution on F5 Big‑IP APM.

    05112212.1K
    57.9K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/27追加) 🛡️No.1555 CVE-2025-53521 F5 BIG-IP Remote Code Execution Vulnerability ==================================== ✅概要 ・深刻度:緊急🔥 9.3 (CVSS Base) / NVD ・種別:制限またはスロットリング無しのリソースの割り当て (CWE-770) ・CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N F5 BIG-IP において、未認証の攻撃者によりリモートから細工されたリクエストを送信することで、任意コードを実行される恐れ。 ✅ChatGPTによる脆弱性評価 ・国内影響度判定:高 ・悪用難易度:低 ✅攻撃前提条件 ・対象システムがネットワーク経由で到達可能 ・脆弱なバージョンが稼働していること ✅悪用時影響 ・未認証でのリモートコード実行 ・機密情報の窃取 ・システム改ざん ・サービス停止 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:確認できず ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-53521 https://my.f5.com/manage/s/article/K000156741 https://www.cisa.gov/news-events/alerts/2026/03/27/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CISA confirmed that F5 BIG‑IP CVE‑2025‑53521 is actively exploited; no proof of concept or exploit code is detailed, but technical and impact information is provided.

    0201346.5K
    42.9K followersView on X
  • ANSSI@ANSSI_FR
    Disclosure

    ⚠ Vulnérabilité F5 BIG-IP Access Policy Manager. 📢 Le CERT-FR a publié une alerte de sécurité concernant la vulnérabilité CVE-2025-53521 affectant BIG-IP Access Policy Manager (APM) de l’éditeur F5. ➡️ + d'infos sur le site du CERT-FR : https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-004/ https://t.co/7GRMrSfotA

    Post summary

    CERT-FR has issued a security alert announcing CVE-2025-53521 against F5 BIG-IP Access Policy Manager, directing readers to the alert page for further details.

    060845.5K
    83.9K followersView on X
  • MigawariIV@strinsert1Na
    Disclosure

    大器晩成型だ > 同脆弱性情報は当初、サービス運用妨害の脆弱性として公表されていましたが、今回の更新において、認証を必要としないリモートコードの実行につながる脆弱性に変更されました。 F5 BIG-IP Access Policy Managerの脆弱性(CVE-2025-53521)に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260007.html

    Post summary

    JPCERT’s notice indicates that CVE‑2025‑53521 in F5 BIG‑IP Access Policy Manager has been re‑classified from a denial‑of‑service flaw to an unauthenticated remote code execution vulnerability, with no exploit, PoC, or active abuse reported.

    100751.9K
    5.0K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    Attackers are exploiting RCE vulnerability in BIG-IP APM systems (CVE-2025-53521) https://www.helpnetsecurity.com/2026/03/28/big-ip-apm-vulnerability-cve-2025-53521-exploited/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    Attackers are actively exploiting CVE‑2025‑53521, an RCE vulnerability in BIG‑IP APM systems, with no patch or mitigation details provided.

    140601.0K
    193.6K followersView on X
  • JPCERTコーディネーションセンター@jpcert
    Active Exploitation

    F5 BIG-IP Access Policy Managerの脆弱性(CVE-2025-53521)に関する注意喚起を公開。2025年10月公表の脆弱性のアドバイザリが更新。リモートコード実行につながる脆弱性で、悪用が確認されています。開発元の最新情報をもとに、対策と侵害有無の調査を実施してください。^KK https://www.jpcert.or.jp/at/2026/at260007.html

    Post summary

    The advisory confirms that CVE-2025-53521, a remote code execution flaw in F5 BIG-IP Access Policy Manager, has been actively exploited, urging stakeholders to investigate incidents and apply mitigations.

    050323.7K
    33.9K followersView on X
  • Densel@luckyhacker43
    Active Exploitation

    CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation ⚡️ 🔗 https://x.com/DefusedCyber/status/2037669147824488867 🔗 https://thehackernews.com/2026/03/cisa-adds-cve-2025-53521-to-kev-after.html Join team 👉https://t.me/luckyhacker43 https://t.co/fIanfMTeoX

    Post summary

    CISA has added CVE-2025-53521 to the KEV list after reporting active exploitation against F5 BIG‑IP APM, confirming real‑world attacks.

    00053443
    2.8K followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    CISAがCVE-2025-53521をKEVに追加し悪用が確認、重要なのは既に実際の攻撃で利用されている脆弱性として優先対応が必要な点 この脆弱性は実環境での悪用が観測され、政府機関や組織に対し期限付きでのパッチ適用が求められている 詳細な攻撃手法は限定的だが、既知脆弱性の迅速な武器化という近年のトレンドと一致 ProxyShellやMOVEitなど過去の大規模悪用事例と同様、公開後短期間で攻撃に組み込まれるパターン KEV入りは「既に攻撃に使われている」シグナルであり優先度は最高レベル APT: 不明 Malware: 記載なし CVE: CVE-2025-53521 IoC: 記載なし #CyberSecurity #Vulnerability #CISA #KEV https://thehackernews.com/2026/03/cisa-adds-cve-2025-53521-to-kev-after.html

    Post summary

    CISA added CVE-2025-53521 to KEV after confirming active exploitation, urging timely patching.

    01052810
    3.5K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    PoisonedRefresh is a fileless Linux rootkit targeting F5 BIG-IP APM, injecting PHP web shells entirely into Apache process memory via CVE-2025-53521, an actively exploited unauthenticated RCE. - CVE-2025-53521 is the initial access vector: an unauthenticated RCE in BIG-IP APM when an access policy is configured on a virtual server. Previously misclassified as a DoS issue, F5 confirmed RCE status. Shadowserver counted 795 exposed endpoints at disclosure. Patch and follow F5 compromise-assessment guidance before any other hardening. - PoisonedRefresh (Sophos: Linux/Agnt-IC) is stage two. It intercepts __libc_start_main before Apache logging initializes, hooks apr_dso_load to wait for libphp, then patches mmap behavior inside libphp so Apache worker processes see a web shell prepended to legitimate BIG-IP APM webtop files (apm_css.php3, full_wt.php3, webtop_popup_css.php3). The on-disk files are never touched. SHA-256: 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9. - The web shell triggers on the magic prefix BSOHAzPB in php://input, decrypts commands with key wSLjN1beuR, and responds HTTP 201 with Content-Type: text/css to blend into normal APM traffic. A UNIX socket at /run/bigtlog.pipe (token Kzwd6jM5) provides an interactive bash shell without opening any TCP port. - Stage one hides inside a trojanized umount binary, infects /usr/sbin/httpd, and embeds in BIG-IP upgrade images for persistence across device updates. #DFIR_Radar

    Post summary

    The post details an actively exploited RCE in F5 BIG‑IP APM (CVE‑2025‑53521), describing a fileless rootkit (PoisonedRefresh) that injects PHP web shells and notes available patches.

    21031322
    2.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appf5big-ip_access_policy_manager---

Explore more