HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

PoisonedRefresh Fileless Linux Rootkit Exploits Unauthenticated RCE in F5 BIG‑IP APM

A new file‑less Linux rootkit, PoisonedRefresh, injects PHP web shells into F5 BIG‑IP APM memory via CVE‑2025‑53521, bypassing traditional detection. The issue underscores the importance of continuous vulnerability remediation and audit‑ready evidence for control assurance.

Verisq™ Intelligence · 📅 September 09, 2026 · 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

PoisonedRefresh Fileless Linux Rootkit Exploits Unauthenticated RCE in F5 BIG‑IP APM

What Happened – A new file‑less Linux rootkit, dubbed PoisonedRefresh, was discovered injecting PHP web shells directly into the memory of F5 BIG‑IP Access Policy Manager (APM) Apache processes. The rootkit is delivered via CVE‑2025‑53521, an unauthenticated remote‑code‑execution flaw in BIG‑IP APM when an access policy is configured on a virtual server.

Why It Matters for Trust & Control Assurance

  • Demonstrates how a missing patch can bypass traditional file‑based detection, undermining the control objective of Vulnerability Management & Patch Assurance.
  • Highlights the need for continuous, evidence‑driven verification that critical assets are running fully remediated firmware – a core requirement of a control‑assurance program.
  • Aligns with Verisq’s Control Mapping capability, which helps organizations map remediation evidence to the VCF control “Maintain up‑to‑date vulnerability remediation processes” and generate audit‑ready artifacts.

Who Is Affected – Enterprises that deploy F5 BIG‑IP APM (network, cloud, and data‑center environments), spanning finance, healthcare, telecom, and other regulated sectors.

Recommended Actions

  • Verify your BIG‑IP APM version against the F5 advisory and apply the patched release immediately.
  • Conduct a post‑patch compromise assessment per F5 guidance to detect any lingering in‑memory shells.
  • Integrate automated patch‑validation checks into your continuous control‑monitoring pipeline to produce defensible evidence for auditors.

Technical Notes

  • Initial access: unauthenticated RCE via CVE‑2025‑53521.
  • First‑stage payload hides in a modified umount binary, modifies SELinux, and embeds in upgrade images for persistence.
  • Second‑stage ELF binary injects itself before Apache’s __libc_start_main, evading file‑system logs and many host‑based IDS.
  • No disk artifacts; detection relies on memory forensics or runtime integrity monitoring.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/198746/malware/poisonedrefresh-a-fileless-linux-rootkit-that-injects-php-web-shells-into-f5-big-ip-apm-server-memory.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →