<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/marques/f5.xml</id>
  <title>Exploit Radar: exploited F5 vulnerabilities</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities for F5 products.</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/marques/f5.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/marques/f5/"/>
  <updated>2026-09-22T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-94127/</id>
    <title>CVE-2026-94127 — F5 BIG-IP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-94127/"/>
    <updated>2026-09-22T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from F5; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 22, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-53521/</id>
    <title>CVE-2025-53521 — F5 BIG-IP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-53521/"/>
    <updated>2026-03-27T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from F5; if none are available, stop using the product. For cloud services, follow the guidance from F5. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on March 27, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-46747/</id>
    <title>CVE-2023-46747 — F5 BIG-IP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-46747/"/>
    <updated>2023-10-31T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from F5; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on October 31, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-46748/</id>
    <title>CVE-2023-46748 — F5 BIG-IP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-46748/"/>
    <updated>2023-10-31T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from F5; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on October 31, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-1388/</id>
    <title>CVE-2022-1388 — F5 BIG-IP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-1388/"/>
    <updated>2022-05-10T00:00:00Z</updated>
    <summary type="text">Apply the security update from F5. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on May 10, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-22991/</id>
    <title>CVE-2021-22991 — F5 BIG-IP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-22991/"/>
    <updated>2022-01-18T00:00:00Z</updated>
    <summary type="text">Apply the security update from F5. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on January 18, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-5902/</id>
    <title>CVE-2020-5902 — F5 BIG-IP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-5902/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from F5. CISA deadline: 181 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-22986/</id>
    <title>CVE-2021-22986 — F5 BIG-IP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-22986/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from F5. CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
</feed>
