F5 BIG-IP flaw reclassified from DoS to pre-auth RCE after active exploitation
A denial-of-service bug patched five months ago turned out to be unauthenticated RCE with CVSS 9.8. F5 confirmed nation-state exploitation of CVE-2025-53521 in BIG-IP APM, and CISA gave federal agencies three days to patch. 240,000+ instances are exposed.
Read more →