CVE-2025-53521
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CRITICAL · CVSS 9.8
⚠ CISA KEV
EPSS 0.08766
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- EPSS percentile: top 7% of all CVEs by exploitation likelihood
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0