F5, Inc. develops a broadly represented portfolio of network security and application delivery appliances, including load balancers, firewalls, and access-control platforms that occupy critical positions in enterprise infrastructure and sit between clients and protected resources. The vendor's vulnerability footprint spans flagship products such as BIG-IP Access Policy Manager, Application Security Manager, and Advanced Firewall Manager, which concentrate risk around input validation, cross-site scripting, resource-consumption, and pointer-dereference weaknesses typical of edge-facing middleware that processes untrusted traffic at scale. A meaningful share of vulnerabilities affecting this vendor reach serious severity, reflecting the security-sensitive role these appliances play in network perimeters and the complexity of stateful protocol handling in high-throughput environments. Defenders should treat F5 advisories as broadly applicable to internet-facing infrastructure and prioritize patching given the vendor's ubiquity in load-balancing and application-protection deployments. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by F5, Inc. over time
Of all the CVEs published by F5, Inc. as a CNA, 99.3% affect products that F5, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by F5, Inc., 78.5% are self-published by F5, Inc. as a CNA.
Signals from CVEs in this vendor scope (1032 CVEs).
1,032 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1388CRITICAL On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x ver | May 5, 2022 | 9.8 | 99 | YES | YES |
CVE-2021-22986CRITICAL On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7. | Mar 31, 2021 | 9.8 | 99 | YES | YES |
CVE-2020-5902CRITICAL In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Co | Jul 1, 2020 | 9.8 | 99 | YES | YES |
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2023-46747CRITICAL Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addre | Oct 26, 2023 | 9.8 | 98 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2021-40438CRITICAL A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 9.0 | 97 | YES | YES |
CVE-2021-22991CRITICAL On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual serve | Mar 31, 2021 | 9.8 | 90 | YES | NO |
CVE-2009-3555CRITICAL The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, | Nov 9, 2009 | 9.8 | 85 | NO | YES |
Signals from CVEs in this vendor scope (1032 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by F5, Inc..
Media articles that mention a CVE ID that affects a product developed by F5, Inc. — matched by CVE ID, not by vendor name.