Critical Known exploited (KEV) CVE-2025-53521

Stack-based buffer overflow in F5 BIG-IP (CVE-2025-53521) — possible remote code execution on an edge device; CVSS 9.8

F5 BIG-IP Added to KEV Mar 27, 2026 Federal remediation due 2026-03-30

F5 BIG-IP (the APM module), an edge device handling application delivery and access control, contains a stack-based buffer overflow flaw (CWE-121). An attacker may achieve remote code execution. The CVSS published on NVD is 9.8 (CRITICAL). CISA added it to the KEV on 2026-03-27, due 2026-03-30 (3 days).

Key facts

  • CVE IDCVE-2025-53521
  • CVSS base score9.8 CRITICAL
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Affected (vendor / product)F5 BIG-IP
  • CWECWE-121
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-03-30 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Stack-based buffer overflow (CWE-121) in F5 BIG-IP (APM module) — possible remote arbitrary code execution.
  • The CVSS published on NVD is 9.8 (CRITICAL; AV:N/AC:L/PR:N/UI:N/C:H/I:H/A:H).
  • BIG-IP is an edge device handling load balancing, application delivery, and VPN — first to receive outside access.
  • Like Citrix NetScaler, seizing an edge device is an entry point to the interior — weighty as the origin of damage.
  • CISA added it to the KEV on 2026-03-27, due 2026-03-30 (3 days). The response is updating per F5's guidance.

A stack-based buffer overflow is a defect in which data is written beyond an allocated region on the "stack" a program uses as temporary workspace, corrupting adjacent control information (such as the return address). Exploited precisely, an attacker can hijack the program's flow of execution and run arbitrary code. This is said to be possible in F5 BIG-IP's Access Policy Manager (APM) module.

What matters is that BIG-IP is an "edge device." BIG-IP handles load balancing, application delivery, and remote access (VPN), placed at the internet boundary that first receives access from outside. Like the Citrix NetScaler covered separately on this site, such edge devices are exposed to the internet at all times and, once seized, become the entry point to the interior — a prime target for attackers. Remote code execution on an edge device is extremely weighty as the origin of damage.

The CVSS published on NVD is 9.8 (CRITICAL), the highest tier, with unauthenticated, remote, no-user-interaction conditions met. CISA's short 3-day remediation window underscores the urgency. The response is prompt updating per F5's guidance.

Why it matters

Remote code execution on an edge device ties directly to surrendering the entry point to the internal network — extremely weighty as the origin of damage. The CVSS published on NVD is 9.8 (CRITICAL), with exploitation conditions met. Like Citrix NetScaler, edge devices exposed to the internet are targets, and CISA's 3-day deadline signals urgency. F5 operators should prioritize updating per F5's guidance and reviewing edge-device exposure.

FAQ

What is a stack-based buffer overflow?
A defect where data is written beyond an allocated region on the "stack" a program uses as workspace, corrupting control information such as the return address. Exploited precisely, an attacker can hijack execution flow and run arbitrary code.
Why is an edge device being targeted serious?
Edge devices like BIG-IP first receive access from outside and are exposed to the internet at all times. Once seized, they become the entry point to the internal network — weighty as the origin of damage and a prime target for attackers.
What should I do?
Update promptly per F5's guidance. CISA set a short 3-day deadline; remote code execution on an edge device is pressing and warrants top-priority action.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#F5#BIG-IP#CWE-121#Buffer overflow#Edge device#VPN#KEV#Remote code execution
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.