LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-53521: F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 27, 2026
CVSS 9.3 · Critical⚠ Actively exploited (CISA KEV)
9.3
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Mar 30, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-53521 to its Known Exploited Vulnerabilities catalog on Mar 27, 2026, with a federal patch deadline of Mar 30, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

This vulnerability is a stack-based buffer overflow in F5 BIG-IP Access Policy Manager (APM) that could allow remote code execution. It affects appliances that enforce remote access and authentication policies, making successful exploitation a direct path to control of traffic inspection and user sessions.

How it works

CWE-121 describes a stack-based buffer overflow in which data written past the end of a fixed-size buffer on the call stack can corrupt adjacent memory. In this class of flaw an attacker supplies crafted input that exceeds the allocated buffer, potentially overwriting return addresses or control structures. When the affected code path executes, the corrupted state can redirect execution to attacker-controlled locations, resulting in remote code execution.

Am I affected? How to find it in your systems

Inventory all F5 BIG-IP devices that have the APM module enabled. Review configuration to identify virtual servers and access profiles that use APM features. Confirm the exact software version and hotfix level running on each unit against the vendor advisory, as only specific builds contain the vulnerable code path. Examine logs for anomalous APM-related requests, unexpected process crashes, or memory-related error messages that precede service restarts.

How to remediate

Apply the vendor-supplied update referenced in the official advisory. After patching, verify that the updated build is active on all affected devices and that APM configurations remain functional. For this weakness class, ensure that input-handling paths receive only validated data sizes and that stack protections such as canaries remain enabled in the running image.

If you can't patch immediately

If your data may have been exposed

Remote code execution on appliances that handle authentication and access decisions can lead to data exposure. Organizations can run a free exposure scan of their domains to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedF5 · BIG-IP
WeaknessCWE-121
CVSS base score9.3 (Critical)
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
PublishedOct 15, 2025
Added to CISA KEVMar 27, 2026
Federal patch deadlineMar 30, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities