type: cve ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [cve, f5, big-ip, rce, active-exploitation, rootkit] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, financial-services] ยท au_impact: true
CVE-2025-53521 is a critical remote code execution (RCE) vulnerability in F5 BIG-IP products that F5 reclassified from a denial-of-service problem in March 2026 and which is assessed as the likely entry vector for a second-stage Linux rootkit ("PoisonedRefresh") targeting BIG-IP APM environments. Sophos and ESET analysed the malware, which intercepts PHP file loading and injects a fileless web shell into memory (no disk write), hides key strings with RC4, hooks the Apache Portable Runtime module loader to gain execution before main(), and creates a password-protected local socket backdoor with SELinux-modification persistence. ShadowServer reported roughly 795 BIG-IP APM endpoints remained exposed online in early September 2026.
| Attribute | Detail |
|---|---|
| CVE | CVE-2025-53521 |
| Type | Remote code execution |
| Exploited | In the wild (entry for PoisonedRefresh rootkit) |
| Affected | F5 BIG-IP / BIG-IP APM |
| Source | Sophos / ESET โ Tier 1/4 |