Vendor

F5

As of , 8 F5 vulnerabilities are on CISA's list of exploited vulnerabilities, 4 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2026-94127.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-94127Heap-based Buffer OverflowF5 BIG-IP APMPatch nowForensic triage required by CISA0.02
2CVE-2023-46747Authentication BypassF5 BIG-IP Configuration UtilityPatch this weekRansomware use; Metasploit module; EPSS 0.970.97
3CVE-2022-1388Missing AuthenticationF5 BIG-IPPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
4CVE-2020-5902Traffic Management User Interface (TMUI) Remote Code ExecutionF5 BIG-IPPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
5CVE-2021-22986iControl REST Remote Code ExecutionF5 BIG-IP and BIG-IQ Centralized ManagementPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
6CVE-2021-22991Buffer OverflowF5 BIG-IP Traffic Management MicrokernelPatch this weekEPSS 0.610.61
7CVE-2023-46748SQL InjectionF5 BIG-IP Configuration UtilityPatch soon0.04
8CVE-2025-53521Stack-Based Buffer OverflowF5 BIG-IPPatch soon0.02

Products

  • BIG-IP3 entries
  • BIG-IP Configuration Utility2 entries
  • BIG-IP and BIG-IQ Centralized Management1 entry
  • BIG-IP APM1 entry
  • BIG-IP Traffic Management Microkernel1 entry

Added each year

0.511.522021: 2220212022: 2220222023: 2220232024: nonenone20242025: nonenone20252026: 222026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20212
20222
20232
2024none
2025none
20262

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-53521 F5 BIG-IPEdited: weakness list, description and name.
  2. CVE-2025-53521 F5 BIG-IPEdited: description.

Every change we recorded