Skip to content
cve — cve-2025-53521

grep -rl "CVE-2025-53521" ./articles

CVE-2025-53521

Sophos documented malware that infects the Apache binary on F5 BIG-IP APM, hooks the runtime as PHP loads, and writes a web shell into memory in front of three real scripts. File integrity checks pass. The entry point, CVE-2025-53521, was published as a DoS in October 2025 and reclassified as unauthenticated RCE five months later.

1 article — 2026-09-09

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered