Vulnerability affecting F5 BIG-IP APM
Organisations have been encouraged to take action against a vulnerability affecting F5 BIG-IP Access Policy Manager.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Organisations have been encouraged to take action against a vulnerability affecting F5 BIG-IP Access Policy Manager.

The NCSC is encouraging UK organisations to take immediate action to mitigate an unauthenticated remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager (CVE-2025-53521). F5 BIG-IP APM is a common component, especially within large enterprises.
F5 has published an updated security advisory explaining that a previously disclosed vulnerability in BIG-IP APM has been recategorised as an unauthenticated remote code execution vulnerability
CVE-2025-53521: When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
F5 is aware of active exploitation of CVE-2025-53521 affecting BIG-IP APM.
The NCSC is working to fully understand UK impact and any potential cases of active exploitation affecting UK networks.
The NCSC recommends investigating for compromise on all affected products regardless of when the system was updated. F5 have published Indicators of Compromise.
All organisations using BIG-IP APM are affected by this vulnerability.
The NCSC recommends following vendor best-practice advice to mitigate vulnerabilities. In this case due to reports of in the wild exploitation, if you use an affected product, you should take these priority actions:
The following NCSC guidance and services will help to secure systems:


