CyberMax
Home › Exploited CVEs

F5 known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 8 F5 CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-09-22), and 4 are known to be used in ransomware campaigns.

F5 CVEs added to CISA KEV per year
2021: 2202122022: 2202222023: 2202322026: 220262

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected F5 products

BIG-IP (3), BIG-IP Configuration Utility (2), BIG-IP APM (1), BIG-IP Traffic Management Microkernel (1), BIG-IP and BIG-IQ Centralized Management (1).

All F5 CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-94127BIG-IP APMBIG-IP APM Heap-based Buffer Overflow2026-09-222026-09-252.2%–
CVE-2025-53521BIG-IPBIG-IP Stack-Based Buffer Overflow2026-03-272026-03-302.3%–
CVE-2023-46748BIG-IP Configuration UtilityBIG-IP Configuration Utility SQL Injection2023-10-312023-11-214.5%–
CVE-2023-46747BIG-IP Configuration UtilityBIG-IP Configuration Utility Authentication Bypass2023-10-312023-11-2196.5%Yes
CVE-2022-1388BIG-IPBIG-IP Missing Authentication2022-05-102022-05-31100.0%Yes
CVE-2021-22991BIG-IP Traffic Management MicrokernelBIG-IP Traffic Management Microkernel Buffer Overflow2022-01-182022-02-0161.1%–
CVE-2021-22986BIG-IP and BIG-IQ Centralized ManagementBIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution2021-11-032021-11-1799.9%Yes
CVE-2020-5902BIG-IPBIG-IP Traffic Management User Interface (TMUI) Remote Code Execution2021-11-032022-05-03100.0%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors