Skip to main content
CISA Known Exploited Vulnerabilities

F5 BIG-IP Stack-Based Buffer Overflow Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2026-03-27
Remediation due
2026-03-30

Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA notes
Please adhere to F5’s guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible F5 products affected by this vulnerability. For more information please see: https://my.f5.com/manage/s/article/K000156741 ; https://my.f5.com/manage/s/article/K000160486 ; https://my.f5.com/manage/s/article/K11438344 ; https://nvd.nist.gov/vuln/detail/CVE-2025-53521

Description

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Severity

CVSS 3.1 · CNA9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 4.0 · CNA9.3 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
SSVC · CISA-ADP
Exploitationactive
Automatableyes
Technical impacttotal

Affected Products

VendorProductAffected versions
F5BIG-IP
17.5.0 to <17.5.1.3
17.1.0 to <17.1.3
16.1.0 to <16.1.6.1
15.1.0 to <15.1.10.8

References

1 Links

Record Details

Published
2025-10-15
Last updated
2026-03-31
Assigner (CNA)
f5
Credited to
F5 would like to thank Kristian Vlaardingerbroek, Hugo Trippaers, and other people of Schuberg Philis; Bart Vrancken; Fox-IT; and the National Cyber Security Centre (NCSC) in the Netherlands for their assistance in investigating this issue and following the highest standards of coordinated disclosure.

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.