Product of F5

BIG-IP

As of , 3 F5 BIG-IP vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2022-1388.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2022-1388Missing AuthenticationF5 BIG-IPPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
2CVE-2020-5902Traffic Management User Interface (TMUI) Remote Code ExecutionF5 BIG-IPPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
3CVE-2025-53521Stack-Based Buffer OverflowF5 BIG-IPPatch soon0.02

Added each year

0.512021: 1120212022: 1120222023: nonenone20232024: nonenone20242025: nonenone20252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20211
20221
2023none
2024none
2025none
20261

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-53521 F5 BIG-IPEdited: weakness list, description and name.
  2. CVE-2025-53521 F5 BIG-IPEdited: description.

Every change we recorded