Stack-based buffer overflow in F5 BIG-IP (CVE-2025-53521) — possible remote code execution on an edge device; CVSS 9.8
F5 BIG-IP (the APM module), an edge device handling application delivery and access control, contains a stack-based buffer overflow flaw (CWE-121). An attacker may achieve remote code execution. The CVSS published on NVD is 9.8 (CRITICAL). CISA added it to the KEV on 2026-03-27, due 2026-03-30 (3 days).
Key facts
- CVE IDCVE-2025-53521
- CVSS base score9.8 CRITICAL
- CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Affected (vendor / product)F5 BIG-IP
- CWECWE-121
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-03-30 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Stack-based buffer overflow (CWE-121) in F5 BIG-IP (APM module) — possible remote arbitrary code execution.
- The CVSS published on NVD is 9.8 (CRITICAL; AV:N/AC:L/PR:N/UI:N/C:H/I:H/A:H).
- BIG-IP is an edge device handling load balancing, application delivery, and VPN — first to receive outside access.
- Like Citrix NetScaler, seizing an edge device is an entry point to the interior — weighty as the origin of damage.
- CISA added it to the KEV on 2026-03-27, due 2026-03-30 (3 days). The response is updating per F5's guidance.
- Of the 1,687 records held as of 2026-09-01, only 50 carry a CVSS score.
1A stack-based buffer overflow
A stack-based buffer overflow is a defect in which data is written beyond an allocated region on the "stack" a program uses as temporary workspace, corrupting adjacent control information (such as the return address). Exploited precisely, an attacker can hijack the program's flow of execution and run arbitrary code. This is said to be possible in F5 BIG-IP's Access Policy Manager (APM) module.
2BIG-IP as an edge device
What matters is that BIG-IP is an "edge device." BIG-IP handles load balancing, application delivery, and remote access (VPN), placed at the internet boundary that first receives access from outside. Like the Citrix NetScaler covered separately on this site, such edge devices are exposed to the internet at all times and, once seized, become the entry point to the interior — a prime target for attackers. Remote code execution on an edge device is extremely weighty as the origin of damage.
3A CVSS of 9.8, the top tier
The CVSS published on NVD is 9.8 (CRITICAL), the highest tier, with unauthenticated, remote, no-user-interaction conditions met. CISA's short 3-day remediation window underscores the urgency. The response is prompt updating per F5's guidance.
4Few entries carry a CVSS score
A KEV entry does not necessarily include CVSS, the numeric score of severity. Counting the records this site holds that carry a value leaves only a small share.
That most entries carry no number means sorting KEV by severity to set priorities does not work as it stands. What KEV supplies is not a ranking of severity but the fact of confirmed exploitation and a remediation date. BIG-IP handles load balancing, application delivery and remote access, sitting at the boundary that first receives access from outside, so taking it opens the way inward.
Why it matters
Remote code execution on an edge device ties directly to surrendering the entry point to the internal network — extremely weighty as the origin of damage. The CVSS published on NVD is 9.8 (CRITICAL), with exploitation conditions met. Like Citrix NetScaler, edge devices exposed to the internet are targets, and CISA's 3-day deadline signals urgency. F5 operators should prioritize updating per F5's guidance and reviewing edge-device exposure.
FAQ
What is a stack-based buffer overflow?
Why is an edge device being targeted serious?
What should I do?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).