Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

F5, Inc.

First CVE: Nov 8, 1999Active for: 27 yearsTotal CVEs: 1,032
64.7
VTI Score
TOP TARGET

F5, Inc. develops a broadly represented portfolio of network security and application delivery appliances, including load balancers, firewalls, and access-control platforms that occupy critical positions in enterprise infrastructure and sit between clients and protected resources. The vendor's vulnerability footprint spans flagship products such as BIG-IP Access Policy Manager, Application Security Manager, and Advanced Firewall Manager, which concentrate risk around input validation, cross-site scripting, resource-consumption, and pointer-dereference weaknesses typical of edge-facing middleware that processes untrusted traffic at scale. A meaningful share of vulnerabilities affecting this vendor reach serious severity, reflecting the security-sensitive role these appliances play in network perimeters and the complexity of stateful protocol handling in high-throughput environments. Defenders should treat F5 advisories as broadly applicable to internet-facing infrastructure and prioritize patching given the vendor's ubiquity in load-balancing and application-protection deployments. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
1,032
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
1.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by F5, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 1999
26 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Self-Reporting Analysis

Of all the CVEs published by F5, Inc. as a CNA, 99.3% affect products that F5, Inc. develops as a vendor.

99.3%
Self-reported: 810 (99.3%)
Third-party: 6 (0.7%)

Of all the CVEs published that affect products developed by F5, Inc., 78.5% are self-published by F5, Inc. as a CNA.

78.5%
21.5%
Self-published: 810 (78.5%)
Other CNAs: 222 (21.5%)

Products(284 total)

Top CVEs

Signals from CVEs in this vendor scope (1032 CVEs).

1,032 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-1388CRITICAL
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x ver
May 5, 20229.899YESYES
CVE-2021-22986CRITICAL
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.
Mar 31, 20219.899YESYES
CVE-2020-5902CRITICAL
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Co
Jul 1, 20209.899YESYES
CVE-2014-6271CRITICAL
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
CVE-2023-46747CRITICAL
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addre
Oct 26, 20239.898YESYES
CVE-2014-7169CRITICAL
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri
Sep 25, 20149.898YESYES
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2021-40438CRITICAL
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20219.097YESYES
CVE-2021-22991CRITICAL
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual serve
Mar 31, 20219.890YESNO
CVE-2009-3555CRITICAL
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier,
Nov 9, 20099.885NOYES
View all 1,032 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,032 CVEs
38%
54%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local111 (10.8%)
Network821 (79.6%)
Unknown81 (7.8%)
Physical3 (0.3%)
Adjacent Network16 (1.6%)
Attack Complexity
Low828 (80.2%)
High123 (11.9%)
Unknown81 (7.8%)
User Interaction
None835 (80.9%)
Unknown81 (7.8%)
Required116 (11.2%)
Privileges Required
Low179 (17.3%)
High116 (11.2%)
None656 (63.6%)
Unknown81 (7.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (1032 CVEs).

CISA KEV
13 CVEs
1.3% of CVEs· 99th percentile
Metasploit
13 CVEs
1.3% of CVEs· 97th percentile
Nuclei
7 CVEs
0.7% of CVEs· 95th percentile
ExploitDB
41 CVEs
4.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by F5, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by F5, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For F5, Inc.'s Products

View all 15 CNAs →

Top CWEs