Skip to content

Security1 publisher2 min readPublished

F5 reclassifies CVE-2025-53521 as unauthenticated RCE already used in attacks

JPCERT/CC's 2026-03-30 alert asks BIG-IP APM operators to apply the fix and then check whether the box was already compromised, because F5 now rates its October denial-of-service bug as unauthenticated code execution under attack.

The Watch · Security desk

Illustration accompanying F5 reclassifies CVE-2025-53521 as unauthenticated RCE already used in attacks

What happened

  • F5 revised advisory K000156741 on 2026-03-29 local time, changing CVE-2025-53521 from the denial-of-service issue published in October 2025 to remote code execution that needs no authentication.
  • F5 says attacks exploiting the vulnerability have been confirmed.
  • The affected products are BIG-IP APM 17.5.0 to 17.5.1, 17.1.0 to 17.1.2, 16.1.0 to 16.1.6 and 15.1.0 to 15.1.10.
  • JPCERT/CC issued alert JPCERT-AT-2026-0007 on 2026-03-30 and says it has confirmed that potentially affected products are in use in Japan.
  • JPCERT/CC recommends that operators investigate whether their devices have already been compromised.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Teams that slotted the October advisory into a routine availability queue now own five months of unreviewed exposure on those appliances, and patching leaves that stretch to account for separately.
  • exposure Every BIG-IP APM in the listed ranges becomes a forensic question as well as a patch target, and the answer has to come from evidence on each device.
  • constraint Checking runs on the appliance with an integrity utility and log review, so the effort lands on staff with console access instead of the update pipeline.
  • precedent F5 is publishing indicators under a cluster label, c05d5254, so operators watching only the CVE page are likely to miss the follow-on detail.

About five months separate F5's original October 2025 filing from the 2026-03-29 revision [13]. Through that period the bug sat in queues as a denial-of-service entry [2]. It is now unauthenticated remote code execution, and F5 says exploitation has been observed [3][4].

F5 has published investigation items, commands and integrity-check tooling for reviewing on-disk files and logs [9]. JPCERT/CC points at three F5 articles: K000160486, "Indicators of Compromise for c05d5254"; K00029945 on the sys-eicheck (FIPS) utility; and K11438344, guidance for a BIG-IP system suspected of compromise [10]. Verification runs against files on the appliance itself [9]. Someone needs console access and time on each box.

The affected list is four version ranges across three major branches [14]: 17.5.0 to 17.5.1 and 17.1.0 to 17.1.2 in the 17 series, 16.1.0 to 16.1.6, and 15.1.0 to 15.1.10 [5]. JPCERT expects details of the vulnerability to be published and exploitation to become widespread [7].

The confirmation of attacks is F5's own, relayed in the JPCERT alert [4]. JPCERT does not name an actor or date the first exploitation [15]. Without that date, the review window on a given device runs from whenever the vulnerable version went into service, not from the October advisory [15]. F5 filed its indicators under the label c05d5254 [10]. Operators with information to share are asked to send it to JPCERT's Early Warning Group at [email protected] [12].

What to watch

  • F5 publishing exploitation dates or an actor for c05d5254. Either would pin down the window operators have to review.
  • JPCERT/CC's Early Warning Group reporting confirmed compromises in Japan after its call for information.
  • Publication of technical detail or exploit code for CVE-2025-53521, which JPCERT says it expects.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories