Exploited CVEs / By vendor / F5

F5 vulnerabilities actively exploited

7 F5 CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2025-53521 (BIG-IP, added 2026-03-27). 4 of the 7 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

7 exploited CVEs4 ransomware-linked
Senserva AI Opinion and rich prompt for F5 exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

BIG-IP: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2025-53521BIG-IP2026-03-27CVSS 9.8, EPSS 2%
CVE-2022-1388BIG-IP2022-05-10ransomware, CVSS 9.8, EPSS 100%
CVE-2020-5902BIG-IP2021-11-03ransomware, CVSS 9.8, EPSS 100%

Other F5 products

CVEProductAdded to KEVSignals
CVE-2023-46747BIG-IP Configuration Utility2023-10-31ransomware, CVSS 9.8, EPSS 97%
CVE-2023-46748BIG-IP Configuration Utility2023-10-31CVSS 8.8, EPSS 4%
CVE-2021-22991BIG-IP Traffic Management Microkernel2022-01-18CVSS 9.8, EPSS 61%
CVE-2021-22986BIG-IP and BIG-IQ Centralized Management2021-11-03ransomware, CVSS 9.8, EPSS 100%

Common questions about exploited F5 CVEs

Which F5 vulnerabilities are actively exploited?

As of August 2026, 7 F5 CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are BIG-IP (3). 4 are linked to ransomware campaigns.

What is the newest exploited F5 CVE?

CVE-2025-53521, affecting BIG-IP, added to the CISA KEV catalog on 2026-03-27. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these F5 CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited F5 CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest F5 KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.