F5 known exploited vulnerabilities
CISA lists 8 F5 CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-09-22), and 4 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2020-5902 (BIG-IP): EPSS 100.0%, added 2021-11-03
- CVE-2022-1388 (BIG-IP): EPSS 100.0%, added 2022-05-10
- CVE-2021-22986 (BIG-IP and BIG-IQ Centralized Management): EPSS 99.9%, added 2021-11-03
- CVE-2023-46747 (BIG-IP Configuration Utility): EPSS 96.5%, added 2023-10-31
- CVE-2021-22991 (BIG-IP Traffic Management Microkernel): EPSS 61.1%, added 2022-01-18
Most affected F5 products
BIG-IP (3), BIG-IP Configuration Utility (2), BIG-IP APM (1), BIG-IP Traffic Management Microkernel (1), BIG-IP and BIG-IQ Centralized Management (1).
All F5 CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-94127 | BIG-IP APM | BIG-IP APM Heap-based Buffer Overflow | 2026-09-22 | 2026-09-25 | 2.2% | – |
| CVE-2025-53521 | BIG-IP | BIG-IP Stack-Based Buffer Overflow | 2026-03-27 | 2026-03-30 | 2.3% | – |
| CVE-2023-46748 | BIG-IP Configuration Utility | BIG-IP Configuration Utility SQL Injection | 2023-10-31 | 2023-11-21 | 4.5% | – |
| CVE-2023-46747 | BIG-IP Configuration Utility | BIG-IP Configuration Utility Authentication Bypass | 2023-10-31 | 2023-11-21 | 96.5% | Yes |
| CVE-2022-1388 | BIG-IP | BIG-IP Missing Authentication | 2022-05-10 | 2022-05-31 | 100.0% | Yes |
| CVE-2021-22991 | BIG-IP Traffic Management Microkernel | BIG-IP Traffic Management Microkernel Buffer Overflow | 2022-01-18 | 2022-02-01 | 61.1% | – |
| CVE-2021-22986 | BIG-IP and BIG-IQ Centralized Management | BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution | 2021-11-03 | 2021-11-17 | 99.9% | Yes |
| CVE-2020-5902 | BIG-IP | BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution | 2021-11-03 | 2022-05-03 | 100.0% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors