F5 Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for F5 products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

9

In CISA KEV

7

Beyond CISA KEV

2

Sensor Observed

1

Virtual Patch Available

0

F5 KEVs Added by Year

Loading...

9 F5 KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-53521

BigIP APM Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2021-22986

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd...

Confirmed In CISA 03 Nov 2021
CVE-2020-5902

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface...

Confirmed In CISA 03 Nov 2021
CVE-2021-22991

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,...

Confirmed In CISA 18 Jan 2022
CVE-2022-1388

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to...

Confirmed In CISA 10 May 2022
CVE-2023-46747

BIG-IP Configuration utility unauthenticated remote code execution vulnerability

Confirmed In CISA 31 Oct 2023
CVE-2023-46748

BIG-IP Configuration utility authenticated SQL injection vulnerability

Confirmed In CISA 31 Oct 2023
CVE-2022-41800

Appliance mode iControl REST vulnerability

High Not in CISA 07 Dec 2022
CVE-2016-5700

Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0...

High Not in CISA 03 Oct 2016

Common Vulnerability Classes (CWE)

  • CWE-306 — Missing Authentication for Critical Function 2
  • CWE-121 — Stack-based Buffer Overflow 1
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
  • CWE-284 — Improper Access Control 1
  • CWE-288 — Authentication Bypass Using an Alternate Path or Channel 1
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology