Site navigation

NCSC Issues Ugent Patch Notice of F5 BIG-IP Vulnerability

Elizabeth Greenberg

,

ncsc f5 patch
The National Cyber Security Centre is still working to understand the full impact of the vulnerability to UK organisations.

The NCSC is encouraging UK organisations to take immediate action to mitigate an unauthenticated remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager (CVE-2025-53521).

F5 BIG-IP APM is a common component, especially within large enterprises.

F5 has published an updated security advisory explaining that a previously disclosed vulnerability in BIG-IP APM has been recategorised as an unauthenticated remote code execution vulnerability

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).

F5 is aware of active exploitation of CVE-2025-53521 affecting BIG-IP APM.

The NCSC is working to fully understand UK impact and any potential cases of active exploitation affecting UK networks.

The NCSC recommends investigating for compromise on all affected products regardless of when the system was updated. F5 have published Indicators of Compromise.

All organisations using BIG-IP APM are affected by this vulnerability.


Recommended reading


The NCSC recommends following vendor best-practice advice to mitigate vulnerabilities. In this case due to reports of in the wild exploitation, if you use an affected product, you should take these priority actions:

  1. Read the security advisory and Indicators of Compromise.
  2. If possible, isolate the affected system(s) and replace with a new, fully up-to-date system (NOTE: this may cause service outage).
  3. Fully investigate for evidence of compromise following the vendor guidance (an assured Cyber Incident Response provider can assist). Where this isn’t possible; the affected system should be erased/destroyed and rebuilt as new.
  4. If you believe you have been compromised, and are in the UK, you should report it and consider using an assured Cyber Incident Response provider. You can also report the compromise to the vendor to assist their investigation.
  5. Update to the latest version of the affected product.
  6. Apply any appropriate security hardening.
  7. Re-enable/reintroduce the affected system(s).
  8. Perform continuous threat hunting activities.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data