# CISA Flags Actively Exploited F5 BIG-IP Vulnerability With 9.3 CVSS Score Allowing Remote Code Execution

_Saturday, March 28, 2026 at 5:27 AM EDT · Security · Breaking · Tier 2 — Notable_

![CISA Flags Actively Exploited F5 BIG-IP Vulnerability With 9.3 CVSS Score Allowing Remote Code Execution — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOCtHFfd9TZrhTa9APggVpivUkp_7HLw49145Q93B-76BiG0kkbGOPgViPII25Inn9b8710FjsB1sG716DO1Qh3ikSV88oqwdhSCJ7V2FTWgPq1xaA_UqMVwIEi4zmLnAmXQmbdG2fWAVBx6H_OiHqCOzghwBkuQYy4mYUCIdIyBi54ojbF3rc_OGIPlGc/s1700-e365/f5.jpg)

CISA has added CVE-2025-53521, a critical flaw in F5 BIG-IP Access Policy Manager, to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. The vulnerability carries a CVSS v4 score of 9.3 and allows remote code execution against affected systems. Any organization running F5 BIG-IP APM should treat this as an emergency patch priority.

[Instagram]
CISA has added a critical F5 BIG-IP Access Policy Manager flaw to its Known Exploited Vulnerabilities catalog. The vulnerability (CVE-2025-53521) carries a CVSS v4 score of 9.3 and allows remote code execution. Organizations running F5 BIG-IP APM should patch immediately.

[LinkedIn]
CISA has added CVE-2025-53521, a critical flaw in F5 BIG-IP Access Policy Manager, to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. The vulnerability carries a CVSS v4 score of 9.3 and allows remote code execution against affected systems. Any organization running F5 BIG-IP APM should treat this as an emergency patch priority.

## Sources


---
Canonical: https://techandbusiness.org/newswire/newsDraft.9a7f9a77-131d-41c1-85e5-d064df53b94f
Retrieved: 2026-07-21T23:46:44.027Z
Publisher: Tech & Business (techandbusiness.org)
