CVE-2021-22986Active Exploitation(f5 / big-ip_access_policy_manager)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for f5 big-ip_access_policy_manager systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • big-ip_access_policy_manager
  • big-ip_advanced_firewall_manager
  • big-ip_advanced_web_application_firewall
  • big-ip_analytics

Threat summary

  • Active exploitation appears in 2 classified signals
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-18); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
big-ip_access_policy_managerbig-ip_advanced_firewall_managerbig-ip_advanced_web_application_firewallbig-ip_analyticsbig-ip_application_acceleration_managerbig-ip_application_security_managerbig-ip_ddos_hybrid_defenderbig-ip_domain_name_systembig-ip_fraud_protection_servicebig-ip_global_traffic_manager

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-18: 1Mentions · 2026-03-28: 1Mentions · 2026-04-30: 1Active Exploitation · 2026-03-18: 1Active Exploitation · 2026-03-28: 1Technical Details · 2026-04-30: 103-1803-2804-30
Signal classification2 categories
Active Exploitation
266.7%
General
133.3%
Classification over time
DateTotalLabels
2026-03-181
Active Exploitation1
2026-03-281
Active Exploitation1
2026-04-301
General1
Full discourse3 posts
  • Grok@grok
    Active Exploitation

    F5 BIG-IP has had hundreds of CVEs over its 25+ year run (F5 vendor total ~300 per CVE databases, vast majority tied to BIG-IP products/modules). At least 5-6 major ones actively exploited in the wild: CVE-2020-5902, CVE-2021-22986, CVE-2022-1388, CVE-2023-46747, plus batches like 40+ in 2022 and 44 in 2025. This latest CVE-2025-53521 makes another KEV entry. Keep patching!

    Post summary

    The post highlights that several major F5 BIG‑IP CVEs, including CVE‑2025‑53521, are actively exploited in the wild, urging timely patching.

    00010122
    8.5M followersView on X
  • David@davidsheyi
    Active Exploitation

    1/ LockBit emerged around 2019, notorious for its Ransomware-as-a-Service model. They’ve exploited vulnerabilities like CVE-2021-22986 to devastating effect. #LockBit #ThreatIntel

    Post summary

    The message states that LockBit has actively exploited CVE‑2021‑22986, indicating real‑world attacks.

    1000060
    555 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    @FosoTweets That's the problem; at their level, attackers can exploit CVE-2021-22986, affecting F5's BIG-IP products, allowing for remote code execution. If security is only reactive, we’re one breach away from a disaster.

    Post summary

    The tweet warns that attackers can exploit the known remote‑code‑execution CVE‑2021‑22986 in F5 BIG‑IP, emphasizing the need for effective security measures.

    0000051
    128 followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
Appf5big-ip_access_policy_manager---
Appf5big-ip_advanced_firewall_manager---
Appf5big-ip_advanced_web_application_firewall---
Appf5big-ip_analytics---
Appf5big-ip_application_acceleration_manager---
Appf5big-ip_application_security_manager---
Appf5big-ip_ddos_hybrid_defender---
Appf5big-ip_domain_name_system---
Appf5big-ip_fraud_protection_service---
Appf5big-ip_global_traffic_manager---
Appf5big-ip_link_controller---
Appf5big-ip_local_traffic_manager---
Appf5big-ip_policy_enforcement_manager---
Appf5big-iq_centralized_management---
Appf5ssl_orchestrator---

Explore more