f5
Safeguard articles tagged "f5" — guides, analysis, and best practices for software supply chain and application security.
11 articles
CVE-2021-22986: F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
CVE-2021-22986 affects F5 BIG-IP and BIG-IQ Centralized Management and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2020-5902: F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
CVE-2020-5902 affects F5 BIG-IP and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2021-22991: F5 BIG-IP Traffic Management Microkernel Buffer Overflow
CVE-2021-22991 affects F5 BIG-IP Traffic Management Microkernel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-01-18.
CVE-2022-1388: F5 BIG-IP Missing Authentication Vulnerability
CVE-2022-1388 affects F5 BIG-IP and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-05-10.
CVE-2023-46747: F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
CVE-2023-46747 affects F5 BIG-IP Configuration Utility and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-10-31.
CVE-2023-46748: F5 BIG-IP Configuration Utility SQL Injection Vulnerability
CVE-2023-46748 affects F5 BIG-IP Configuration Utility and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-10-31.
CVE-2025-53521: F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
CVE-2025-53521 affects F5 BIG-IP and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-27.
F5, Check Point, Versa, and Arista: Four Vendors, One Edge Infrastructure Problem
A BIG-IP APM buffer overflow, a ransomware-linked Check Point VPN authentication bypass, a Versa Concerto proxy misconfiguration, and an Arista EOS tunnel decapsulation flaw all failed at the same job: enforcing a boundary.
F5 BIG-IP CVE-2022-1388 Explained: The iControl REST Authentication Bypass
CVE-2022-1388 is an authentication bypass in the F5 BIG-IP iControl REST interface that leads to unauthenticated remote code execution, rated CVSS 9.8. Here is the timeline, root cause, and patched versions.
CVE-2025-53521 in F5 BIG-IP APM: Patch Posture & SBOM Response
F5 BIG-IP APM bug reclassified from DoS to RCE at CVSS 9.8 and landed on CISA KEV. Defender playbook for the late-cycle severity surprise.
F5 BIG-IP CVE-2023-46747: Authentication Bypass Puts Network Infrastructure at Risk
A critical authentication bypass in F5 BIG-IP allowed unauthenticated attackers to gain administrative access. The vulnerability affected the management interface of devices protecting enterprise networks.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.