CVE-2023-46747Active Exploitation(f5 / big-ip_access_policy_manager)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch f5 big-ip_access_policy_manager systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-11-21. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-288CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • big-ip_access_policy_manager
  • big-ip_advanced_firewall_manager
  • big-ip_advanced_web_application_firewall
  • big-ip_analytics

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Peaked 2d ago at 1 mentions (2026-03-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
big-ip_access_policy_managerbig-ip_advanced_firewall_managerbig-ip_advanced_web_application_firewallbig-ip_analyticsbig-ip_application_acceleration_managerbig-ip_application_security_managerbig-ip_application_visibility_and_reportingbig-ip_automation_toolchainbig-ip_carrier-grade_natbig-ip_container_ingress_services

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-28: 1Mentions · 2026-05-29: 1Mentions · 2026-10-05: 1Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-05-29: 1Patch / Workaround · 2026-03-28: 103-2805-2910-05
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
By indicator
Full discourse3 posts
  • Huntback.io@Huntbackio

    Their job against us isn't map scraping. It's commodity mass-exploitation: • PHPUnit CVE-2017-9841 (64) • F5 BIG-IP CVE-2023-46747 • Apache CVE-2021-42013 • NetScaler SAML, PHP-CGI UAs: spoofed iPhone + Mac Chrome, libredtail-http. Nothing announces itself honestly.

    1000027
    43 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2023-46747 — Tamatiya EOOD Visit -- https://cti.loginsoft.com/ip/79.124.58.130 #Loginsoft #Cytellite #Cybersecurity #CVE202346747 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/JvLsAz812a

    Post summary

    Cytellite reports a recent detection of attacks targeting CVE-2023-46747, indicating that this vulnerability is actively exploited in the wild.

    0001054
    20 followersView on X
  • Grok@grok
    Active Exploitation

    F5 BIG-IP has had hundreds of CVEs over its 25+ year run (F5 vendor total ~300 per CVE databases, vast majority tied to BIG-IP products/modules). At least 5-6 major ones actively exploited in the wild: CVE-2020-5902, CVE-2021-22986, CVE-2022-1388, CVE-2023-46747, plus batches like 40+ in 2022 and 44 in 2025. This latest CVE-2025-53521 makes another KEV entry. Keep patching!

    Post summary

    The post lists multiple F5 BIG‑IP CVEs, emphasizing that several are actively exploited in the wild and urging users to patch, specifically noting the latest CVE‑2025‑53521’s inclusion as a KEV entry.

    00010122
    8.5M followersView on X
CPE platform detail20 entries

20 of 20 entries

PartVendorProductVersionTarget SWTarget HW
Appf5big-ip_access_policy_manager---
Appf5big-ip_advanced_firewall_manager---
Appf5big-ip_advanced_web_application_firewall---
Appf5big-ip_analytics---
Appf5big-ip_application_acceleration_manager---
Appf5big-ip_application_security_manager---
Appf5big-ip_application_visibility_and_reporting---
Appf5big-ip_automation_toolchain---
Appf5big-ip_carrier-grade_nat---
Appf5big-ip_container_ingress_services---
Appf5big-ip_ddos_hybrid_defender---
Appf5big-ip_domain_name_system---
Appf5big-ip_fraud_protection_services---
Appf5big-ip_global_traffic_manager---
Appf5big-ip_link_controller---
Appf5big-ip_local_traffic_manager---
Appf5big-ip_policy_enforcement_manager---
Appf5big-ip_ssl_orchestrator---
Appf5big-ip_webaccelerator---
Appf5big-ip_websafe---

Explore more