F5 reclassifies BIG-IP flaw from denial of service to code execution

F5 has updated its advisory for CVE-2025-53521 affecting BIG-IP APM. In the 27 March 2026 update, F5 states this is an unauthenticated remote code execution vulnerability, where it had previously been categorised and remediated as a denial-of-service issue. F5 also states the vulnerability has been exploited, and that the reclassification rests on new information obtained in March 2026. The update should be read alongside F5's 15 October 2025 disclosure cycle, when the issue was originally published and fixed, and alongside the company's broader 2025 security incident, in which a threat actor accessed BIG-IP source code and information about undisclosed vulnerabilities. NVD changed the description the same day, and the CVE was added to CISA's Known Exploited Vulnerabilities catalog.

What this means for your organisation

No new patch has been released. What changed is the understanding of how serious the issue was. For organisations that patched normally in October 2025, the practical consequence is small. For those that deprioritised it because it was labelled denial of service, it is considerable. It illustrates a broader point: severity at publication is a snapshot, and risk decisions resting on it must be open to revision.

Berigo recommends

  • Confirm that your BIG-IP installations actually received the October 2025 update, not merely that it was scheduled.
  • Review which updates you deferred because the severity looked low, and reassess them.
  • Subscribe to CISA's exploited vulnerabilities catalog and let it trigger fresh review of already-closed items.
  • Build the possibility of reclassification into your vulnerability management routine.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch