CISA Adds Actively Exploited F5 BIG-IP Vulnerability to KEV Catalog
The **Cybersecurity and Infrastructure Security Agency (CISA)** has added a new vulnerability, **CVE-2024-53521**, affecting **F5 BIG-IP**, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability, a Remote Code Execution (RCE) flaw, is actively being exploited, posing a significant risk to organizations.
## CISA Flags F5 BIG-IP RCE as Actively Exploited
**CISA** added **CVE-2024-53521**, an **F5 BIG-IP** Remote Code Execution Vulnerability, to its [Known Exploited Vulnerabilities (KEV) Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) based on evidence of active exploitation in the wild.
* [CVE-2024-53521: F5 BIG-IP Remote Code Execution Vulnerability](https://www.cve.org/CVERecord?id=CVE-2025-53521)
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
## Binding Operational Directive (BOD) 22-01
[Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities](https://www.cisa.gov/binding-operational-directive-22-01) established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (**CVEs**) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the [BOD 22-01 Fact Sheet](https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf) for more information.
## Recommendation
Although BOD 22-01 only applies to FCEB agencies, **CISA** strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of [KEV Catalog vulnerabilities](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the [specified criteria](https://www.cisa.gov/known-exploited-vulnerabilities).