security1 publisher
F5 reclassifies CVE-2025-53521 as unauthenticated RCE already used in attacks
JPCERT/CC's 2026-03-30 alert asks BIG-IP APM operators to apply the fix and then check whether the box was already compromised, because F5 now rates its October denial-of-service bug as unauthenticated code execution under attack.
Publishers:jpcert.or.jp
Reality
- Evidence68
- Adoption42
- Hype gap−12
- Incentives32
- Confidence66