F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack Buffer Overflow (CVE-2025-53521) — CISA KEV Active Exploitation by Chinese Nation-State Actor
F5 BIG-IP APM Unauthenticated Remote Code Execution via (TL-2026-0312), also tracked as K000156741, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-04-02. It is attributed to UTA0178 (China) with high confidence, affects F5 BIG-IP APM (Access Policy Manager), references 1 CVE (CVE-2025-53521), maps to 19 MITRE ATT&CK techniques (T1020, T1027, T1036), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-0312
- Threat ID
- TL-2026-0312
- Also known as
- K000156741, K000160486
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-04-02
- Last reviewed
- 2026-04-02
- Attribution
- UTA0178
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government, financial, technology, defense, healthcare, telecommunications, energy, critical-infrastructure
- Target regions
- North America, Europe, Asia Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in F5 BIG-IP APM Unauthenticated Remote Code Execution via
Malware and tooling: BRICKSTORM - S9015, c05d5254
Critical unauthenticated remote code execution vulnerability in F5 BIG-IP Access Policy Manager (APM) actively exploited by a Chinese nation-state threat actor. Originally disclosed as a DoS flaw in October 2025 and reclassified as RCE in March 2026 after F5 confirmed a source code breach. CISA added to KEV on March 27, 2026, with over 14,000 internet-exposed instances identified by Shadowserver.
How F5 BIG-IP APM Unauthenticated Remote Code Execution via works
CVE-2025-53521 is a critical unauthenticated remote code execution vulnerability affecting the apmd process in F5 BIG-IP Access Policy Manager (APM). The vulnerability is a stack-based buffer overflow (CWE-121) triggered when a BIG-IP APM access policy is configured on a virtual server and the system receives specially crafted malicious traffic. Exploitation grants root-level access to the underlying operating system without requiring any authentication.
The vulnerability was initially disclosed on October 15, 2025, and classified as a denial-of-service issue. Concurrently, F5 confirmed a data breach revealing that a highly sophisticated nation-state threat actor had maintained access to F5's internal network for at least 12 months, accessing BIG-IP source code and information about undisclosed vulnerabilities. In March 2026, based on new intelligence, F5 reclassified the vulnerability from DoS to RCE with CVSS scores of 9.8 (v3.1) and 9.3 (v4.0).
Active exploitation has been confirmed by both F5 and CISA. The threat actor — attributed to China — has been observed deploying the Brickstorm backdoor, a custom implant associated with Chinese nation-state operations, on compromised F5 customer systems. Post-exploitation activity includes deployment of in-memory webshells, modification of the sys-eicheck system integrity checker to evade detection, disabling SELinux security modules, injecting SSH authorized keys for persistent access, and modifying system binaries including /usr/bin/umount and /usr/sbin/httpd.
The apmd process handles live access policy traffic and runs with elevated privileges, making it a high-value target. Exploitation is pre-authentication and requires no user interaction. Appliance mode BIG-IP systems are also vulnerable. The attack surface is significant: Shadowserver identified over 14,000 internet-exposed BIG-IP APM instances and over 17,100 total BIG-IP APM fingerprints as of April 2026. F5 serves over 23,000 customers including 48 of the Fortune 50.
F5 has warned that UCS (User Configuration Set) backups from compromised systems may contain persistent malware, advising organizations to rebuild from known-good sources rather than restoring from potentially tainted backups. The Dutch National Cyber Security Center (NCSC-NL) confirmed active abuse on March 30, 2026.
Notably, no public proof-of-concept exploit has been identified, suggesting the exploit is held privately by the threat actor — likely developed using the stolen F5 source code. This significantly increases the sophistication assessment and indicates a well-resourced, persistent adversary with deep knowledge of BIG-IP internals.
MITRE ATT&CK techniques used in TL-2026-0312
exfiltration
T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1134 Access Token Manipulation
collection
T1056 Input Capture; T1213 Data from Information Repositories
execution
T1059 Command and Scripting Interpreter
command-and-control
T1071 Application Layer Protocol; T1571 Non-Standard Port
discovery
T1082 System Information Discovery
persistence
T1098 Account Manipulation; T1505 Server Software Component; T1547 Boot or Logon Autostart Execution
initial-access
T1190 Exploit Public-Facing Application
impact
credential-access
T1539 Steal Web Session Cookie
lateral-movement
defense-impairment
Affected products and versions in F5 BIG-IP APM Unauthenticated Remote Code Execution via
- F5 — BIG-IP APM (Access Policy Manager)
Vulnerable versions: 17.5.0 - 17.5.1; 17.1.0 - 17.1.2; 16.1.0 - 16.1.6; 15.1.0 - 15.1.10
Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8
Remediation for F5 BIG-IP APM Unauthenticated Remote Code Execution via
Patches
- Upgrade BIG-IP APM 17.5.x to version 17.5.1.3 or later
- Upgrade BIG-IP APM 17.1.x to version 17.1.3 or later
- Upgrade BIG-IP APM 16.1.x to version 16.1.6.1 or later
- Upgrade BIG-IP APM 15.1.x to version 15.1.10.8 or later
Immediate actions
- Inventory all F5 BIG-IP APM systems and confirm running versions against vulnerable ranges
- Assess internet exposure of all BIG-IP APM instances — restrict management interface access to known admin IP ranges immediately
- Search for published IOCs: check /run/bigtlog.pipe, verify hashes of /usr/bin/umount and /usr/sbin/httpd, inspect SSH authorized_keys files
- Review iControl REST API logs for unauthorized access from external sources
- Monitor for apmd process spawning unexpected shell processes (/bin/bash, /bin/sh)
Workarounds
- Restrict access to management interfaces to trusted internal networks only
- If patching is not immediately possible, consider disabling APM access policies on internet-facing virtual servers as a temporary mitigation
- Do NOT restore from UCS backups of potentially compromised systems — rebuild from known-good sources
Longer-term hardening
- Implement network segmentation to isolate BIG-IP management interfaces from internet-facing networks
- Deploy EDR with behavioral detection on network appliance management segments
- Forward all BIG-IP logs to external SIEM with extended retention policies
- Implement multi-factor authentication for all administrative access to BIG-IP systems
- Establish continuous monitoring for iControl REST API access patterns
- Conduct forensic analysis on any systems showing IOC matches — assume full compromise
CVEs associated with F5 BIG-IP APM Unauthenticated Remote Code Execution via
Weaknesses (CWE) in F5 BIG-IP APM Unauthenticated Remote Code Execution via
CWE-121
Timeline of F5 BIG-IP APM Unauthenticated Remote Code Execution via
- F5 releases patches for affected BIG-IP APM versions: 17.5.1.3, 17.1.3, 16.1.6.1, and 15.1.10.8.
- F5 confirms nation-state threat actor maintained access to F5 internal network for at least 12 months, accessing BIG-IP source code and undisclosed vulnerability information.
- F5 publishes Security Advisory K000156741, disclosing CVE-2025-53521 as a denial-of-service vulnerability in BIG-IP APM. Concurrently discloses data breach by a highly sophisticated nation-state threat actor who accessed BIG-IP source code.
- F5 publishes IOC advisory K000160486 detailing indicators of compromise including the c05d5254 malware identifier, sys-eicheck modifications, and in-memory webshell deployment.
- CISA adds CVE-2025-53521 to Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Orders federal agencies to mitigate by March 30, 2026.
- F5 reclassifies CVE-2025-53521 from DoS to unauthenticated remote code execution based on new information. CVSS scores updated to 9.8 (v3.1) and 9.3 (v4.0).
- Security researchers report the threat actor is linked to China and may have deployed the Brickstorm backdoor — a custom implant attributed to Chinese nation-state operations — on compromised F5 customer systems.
- Dutch National Cyber Security Center (NCSC-NL) independently confirms active abuse of CVE-2025-53521. Federal deadline for CISA mitigation reached.
- Shadowserver Foundation identifies over 14,000 internet-exposed BIG-IP APM instances and 17,100+ total BIG-IP APM fingerprints globally, indicating massive attack surface.
- Multiple security vendors confirm continued exploitation. Acute scanning activity targeting /mgmt/shared/identified-devices/config/device-info endpoint observed post-KEV listing.
- As of 2026-05-29, CVE-2025-53521 (F5 BIG-IP APM pre-auth RCE) remains a live threat: it sits on CISA KEV (added 2026-03-27), is actively exploited by China-nexus UNC5221 deploying BRICKSTORM webshells, with 14,000+ instances still internet-exposed. Patches from Oct 2025 exist but adoption is poor and no takedown or actor disruption has been reported.
Sources cited for F5 BIG-IP APM Unauthenticated Remote Code Execution via
- CISA KEV Entry — CVE-2025-53521
- F5 Security Advisory K000156741: BIG-IP APM vulnerability CVE-2025-53521
- F5 Security Advisory K000160486: CVE-2025-53521 Indicators of Compromise
- NVD — CVE-2025-53521
- BleepingComputer: Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks
- BleepingComputer: Hackers exploiting critical F5 BIG-IP flaw in attacks
- Help Net Security: Attackers exploiting RCE vulnerability in BIG-IP APM systems
- Hadrian: F5 BIG-IP APM Remote Code Execution Active Exploitation
- Arctic Wolf: CVE-2025-53521 F5 BIG-IP APM Vulnerability Reclassified as RCE
- Qualys ThreatPROTECT: CISA Warns about Active Exploitation of F5 BIG-IP Vulnerability
- Shadowserver Foundation BIG-IP APM Exposure Scan
- eSentire: F5 BIG-IP APM Flaw CVE-2025-53521 Exploited in the Wild
- CyCognito: Emerging Threat F5 BIG-IP APM RCE
Threats related to F5 BIG-IP APM Unauthenticated Remote Code Execution via
Detection coverage for TL-2026-0312
As of 2026-04-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0312 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.