Exploitation timeline
Threadlinqs has recorded 13 F5 CVEs published between and . The busiest month was 2026-05 (4 new CVEs). 5 of them (38%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 13 of 13 tracked F5 CVEs.
- CVE-2020-5902critical 9.8KEVRansomwareEPSS 100%
- CVE-2023-44487high 7.5KEVEPSS 100%
- CVE-2023-46747critical 9.8KEVRansomwareEPSS 96.5%
- CVE-2025-53521critical 9.8KEVEPSS 41.4%
- CVE-2026-94127critical 9.8KEVEPSS 1.4%
- CVE-2026-42530high 8.1EPSS 2.4%
- CVE-2026-42055high 8.1EPSS 1.8%
- CVE-2026-42945high 8.1EPSS 0.9%
- CVE-2026-11311high 8.1EPSS 0.6%
- CVE-2026-50107high 8.1EPSS 0.5%
- CVE-2026-9256high 8.1EPSS 0.2%
- CVE-2026-42946medium 6.5EPSS 0.1%
- CVE-2026-40701medium 4.8EPSS 0%
Products affected
Threadlinqs normalises CPE and CNA product records across all 13 CVEs; 18 distinct F5 products are affected. The most frequently affected:
- NGINX Open Source 6 CVEs
- NGINX Plus 5 CVEs
- Big-ip Access Policy Manager 3 CVEs
- BIG-IP 2 CVEs
- NGINX Gateway Fabric 2 CVEs
- Big-ip Advanced Firewall Manager 1 CVE
- Big-ip Advanced Web Application Firewall 1 CVE
- Big-ip Analytics 1 CVE
- Big-ip Application Acceleration Manager 1 CVE
- Big-ip Application Security Manager 1 CVE
- Big-ip Ddos Hybrid Defender 1 CVE
- Big-ip Domain Name System 1 CVE
- Big-ip Fraud Protection Service 1 CVE
- Big-ip Global Traffic Manager 1 CVE
- Big-ip Link Controller 1 CVE
- Big-ip Local Traffic Manager 1 CVE
- Big-ip Policy Enforcement Manager 1 CVE
- Ssl Orchestrator 1 CVE
Threat activity
22 tracked threat campaigns reference F5 products or exploit F5 CVEs:
- CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud Orchestrator Auth Bypass, F5 BIG-IP APM Heap OverflowCRITICAL
- Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OSMEDIUM
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for Unauthenticated Remote Code ExecutionCRITICAL
- F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)HIGH
- Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via Bundled Fortinet NGFW < V7.4.3 (SSA-832273)CRITICAL
- EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked ActorsHIGH
- AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day (CVE-2026-63078)HIGH
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote AccessMEDIUM
- F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)HIGH
- F5 Patches Multiple NGINX Vulnerabilities: Heap Overflow, Memory Disclosure, and Use-After-Free (CVE-2026-42533, CVE-2026-60005, CVE-2026-56434)CRITICAL
- StrikeShark Campaign: SharkLoader Dropper Targets Governments and Software Developers via N-Day Exploits and Trojanized Installers to Deploy Cobalt StrikeHIGH
- SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt StrikeHIGH
- SharkLoader Malware Deploys Cobalt Strike Beacon via DLL Side-Loading in StrikeShark CampaignHIGH
- F5 Out-of-Band Patches for Critical NGINX HTTP/3 Use-After-Free and Proxy/gRPC Heap Overflow (CVE-2026-42530, CVE-2026-42055) plus NGINX Gateway Fabric Config Injection (CVE-2026-11311, CVE-2026-50107)CRITICAL
- Velvet Ant (Operation Highland): Backdoored Linux PAM and OpenSSH for ~Decade-Long Espionage PersistenceCRITICAL
- Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay (CVE-2025-33073, CVE-2025-53521)HIGH
- F5 BIG-IP Edge Appliance Abused for SSH Pivot → Confluence RCE → CVE-2025-33073 Kerberos Relay to Active Directory (Microsoft Defender Research)HIGH
- Nginx-poolslip CVE-2026-9256 — Pre-Auth Heap Buffer Overflow in NGINX ngx_http_rewrite_module (Patch Bypass of CVE-2026-42945 'NGINX Rift')CRITICAL
- NGINX Rift — CVE-2026-42945 Heap Buffer Overflow in ngx_http_rewrite_module (CVSS v4 9.2 Critical, 18-Year-Old Pre-Auth RCE, Public PoC)CRITICAL
- F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack Buffer Overflow (CVE-2025-53521) — CISA KEV Active Exploitation by Chinese Nation-State ActorCRITICAL
- CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack-based Buffer OverflowCRITICAL
- CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via apmd Process — Active Exploitation by UNC5221 (BRICKSTORM)CRITICAL
Threat actors targeting F5
Named threat actors attributed to campaigns that involve F5 products or CVEs, with the number of linked campaigns:
How to prioritise F5 patching
This order follows the data Threadlinqs holds for F5, not a generic severity checklist:
- 5 of 13 F5 CVEs (38%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2020-5902, CVE-2023-44487, CVE-2023-46747.
- 2 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2026-42530 (2.4%), CVE-2026-42055 (1.8%), CVE-2026-42945 (0.9%).
- 4 CVEs score Critical and 7 High on CVSS v3 (maximum 9.8, average 8.2); sequence these after KEV and high-EPSS items.
- 6 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.