F5 Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for F5 products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
9
In CISA KEV
7
Beyond CISA KEV
2
Sensor Observed
1
Virtual Patch Available
0
F5 KEVs Added by Year
9 F5 KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-53521
BigIP APM Vulnerability |
BIG-IP | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2021-22986
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd... |
BIG-IP; BIG-IQ | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-5902
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface... |
BIG-IP | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22991
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,... |
BIG-IP | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2022-1388
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to... |
BIG-IP | Confirmed | In CISA | 10 May 2022 |
|
CVE-2023-46747
BIG-IP Configuration utility unauthenticated remote code execution vulnerability |
BIG-IP | Confirmed | In CISA | 31 Oct 2023 |
|
CVE-2023-46748
BIG-IP Configuration utility authenticated SQL injection vulnerability |
BIG-IP | Confirmed | In CISA | 31 Oct 2023 |
|
CVE-2022-41800
Appliance mode iControl REST vulnerability |
BIG-IP | High | Not in CISA | 07 Dec 2022 |
|
CVE-2016-5700
Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0... |
BIG-IP | High | Not in CISA | 03 Oct 2016 |
Common Vulnerability Classes (CWE)
- CWE-306 — Missing Authentication for Critical Function 2
- CWE-121 — Stack-based Buffer Overflow 1
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
- CWE-284 — Improper Access Control 1
- CWE-288 — Authentication Bypass Using an Alternate Path or Channel 1
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology