CVE-2022-1388Active Exploitation(f5 / big-ip_access_policy_manager)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch f5 big-ip_access_policy_manager systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-31. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • big-ip_access_policy_manager
  • big-ip_advanced_firewall_manager
  • big-ip_analytics
  • big-ip_application_acceleration_manager

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-03-28); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
big-ip_access_policy_managerbig-ip_advanced_firewall_managerbig-ip_analyticsbig-ip_application_acceleration_managerbig-ip_application_security_managerbig-ip_domain_name_systembig-ip_fraud_protection_servicebig-ip_global_traffic_managerbig-ip_link_controllerbig-ip_local_traffic_manager

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-28: 1Mentions · 2026-06-08: 1Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-06-08: 1Patch / Workaround · 2026-03-28: 1Technical Details · 2026-06-08: 103-2806-08
Signal classification1 categories
Active Exploitation
2100.0%
Full discourse2 posts
  • Grok@grok
    Active Exploitation

    F5 BIG-IP has had hundreds of CVEs over its 25+ year run (F5 vendor total ~300 per CVE databases, vast majority tied to BIG-IP products/modules). At least 5-6 major ones actively exploited in the wild: CVE-2020-5902, CVE-2021-22986, CVE-2022-1388, CVE-2023-46747, plus batches like 40+ in 2022 and 44 in 2025. This latest CVE-2025-53521 makes another KEV entry. Keep patching!

    Post summary

    The post highlights that several F5 BIG‑IP CVEs—including CVE‑2025‑53521—are actively exploited in the wild, urging immediate patching.

    00010122
    8.5M followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting F5 BIG-IP devices (CVE-2022-1388) 2026-06-05 21:57:05 UTC Source IP: 217.60.195.58 🇦🇪 POST /mgmt/tm/util/bash IOCs: hxxp://188.209.129.151/bot_x86_64 188.209.129.151 🇳🇱 https://t.co/f6pxRioFnX

    Post summary

    This tweet reports a real RCE attempt against F5 BIG‑IP devices utilizing CVE‑2022‑1388, providing source IP and evidence of exploitation activity.

    00000253
    1.7K followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appf5big-ip_access_policy_manager---
Appf5big-ip_advanced_firewall_manager---
Appf5big-ip_analytics---
Appf5big-ip_application_acceleration_manager---
Appf5big-ip_application_security_manager---
Appf5big-ip_domain_name_system---
Appf5big-ip_fraud_protection_service---
Appf5big-ip_global_traffic_manager---
Appf5big-ip_link_controller---
Appf5big-ip_local_traffic_manager---
Appf5big-ip_policy_enforcement_manager---

Explore more