Zero-dayMar 30, 2026
F5 BIG-IP Vulnerability Reclassified as RCE, Under Exploitation
F5 BIG-IP CVE-2025-53521 reclassified from DoS to critical RCE under active exploitation.
Summary
F5 BIG-IP vulnerability CVE-2025-53521, originally disclosed in October as a high-severity denial-of-service flaw, has been reclassified as a critical remote code execution (RCE) vulnerability. The bug is now known to be under active exploitation in the wild, significantly raising its threat level and urgency for patching.
Indicators of Compromise
- cve — CVE-2025-53521