Skip to content

F5 BIG-IP Security Advisory – March 2026


CRITICAL: CVE-2025-53521 Escalated to RCE (CVSS 9.8) – Active Exploitation Confirmed

F5 has confirmed that a previously disclosed DoS vulnerability is now a Remote Code Execution (RCE) threat. Immediate patching is required for all BIG-IP Access Policy Manager (APM) instances.

Remediation Table

Affected VersionRequired Patch Version
17.5.x17.5.1.3 or later
17.1.x17.1.3 or later
16.1.x16.1.6.1 or later
15.1.x15.1.10.8 or later
CISA KEV Status: This vulnerability was added to the Known Exploited Vulnerabilities catalog on March 27, 2026. Federal agencies and private enterprises are urged to disconnect or patch management interfaces immediately.
 

Asset Identification Queries (runZero)

Locate potentially compromised software modules:

vendor:=F5 AND product:=”BIG-IP Access Policy Manager”

Locate all F5-based operating systems within the network:

os:=”F5%”

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Discover more from Version 2 Limited

Subscribe now to keep reading and get access to the full archive.

Continue reading