F5 vendor intelligence

F5 Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting F5 products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse F5 KEVs Full KEV feed
Total KEVs
9
Known exploited vulnerabilities affecting F5 products
In CISA KEV
7
Records also listed in the official catalog
Beyond CISA KEV
2
Additional exploited CVEs absent from CISA KEV
Sensor Observed
1
F5 KEV with sensor-observed exploitation activity

The catalog gap matters for F5 exposure

Two of the nine exploited F5 CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 22% of this vendor portfolio.

78%
Covered by CISA
22%
Beyond CISA
2
Product families

Attested F5 CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2025-53521

BigIP APM Vulnerability

BIG-IP Confirmed In CISA 01 Jun 2026
CVE-2021-22986

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd...

BIG-IP; BIG-IQ Confirmed In CISA 03 Nov 2021
CVE-2020-5902

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface...

BIG-IP Confirmed In CISA 03 Nov 2021
CVE-2021-22991

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,...

BIG-IP Confirmed In CISA 18 Jan 2022
CVE-2022-1388

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to...

BIG-IP Confirmed In CISA 10 May 2022
CVE-2023-46747

BIG-IP Configuration utility unauthenticated remote code execution vulnerability

BIG-IP Confirmed In CISA 31 Oct 2023
CVE-2023-46748

BIG-IP Configuration utility authenticated SQL injection vulnerability

BIG-IP Confirmed In CISA 31 Oct 2023
CVE-2022-41800

Appliance mode iControl REST vulnerability

BIG-IP High Beyond CISA 07 Dec 2022
CVE-2016-5700

Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0...

BIG-IP High Beyond CISA 03 Oct 2016

Showing 9 of 9 F5 known exploited vulnerabilities.

Recurring weakness patterns

Missing authentication for critical function, stack-based buffer overflow, and limitation account for four mapped occurrences across this F5 KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.