CVSS v3.1 Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HEPSS Prediction
Documented as more likely to be exploited than 95.4% of known CVEs.
Mar 27, 2026
Mar 30, 2026
Threat Analysis
F5 BIG-IP APM contains an unspecified vulnerability that could allow a threat actor to achieve remote code execution.
Remediation Directive
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
External Intelligence
Please adhere to F5’s guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible F5 products affected by this vulnerability. For more information please see:
https://my.f5.com/manage/s/article/K000156741
https://my.f5.com/manage/s/article/K000160486
https://my.f5.com/manage/s/article/K000160486
https://my.f5.com/manage/s/article/K11438344
https://my.f5.com/manage/s/article/K11438344
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2025-53521