# F5 vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 13 F5 CVEs, 5 in the CISA Known Exploited Vulnerabilities catalog, 2 used in ransomware campaigns, linked to 22 tracked threat campaigns and 4 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 13 F5 CVEs published between 2020-07-15 and 2026-09-15. The busiest month was 2026-05 (4 new CVEs). 5 of them (38%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 13 of 13 tracked F5 CVEs.

- [CVE-2020-5902](https://intel.threadlinqs.com/cve/CVE-2020-5902) — CRITICAL 9.8 · KEV · Ransomware · EPSS 100% · 2020-07-01
- [CVE-2023-44487](https://intel.threadlinqs.com/cve/CVE-2023-44487) — HIGH 7.5 · KEV · EPSS 100% · 2023-10-10
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747) — CRITICAL 9.8 · KEV · Ransomware · EPSS 96.5% · 2023-10-26
- [CVE-2025-53521](https://intel.threadlinqs.com/cve/CVE-2025-53521) — CRITICAL 9.8 · KEV · EPSS 41.4% · 2025-10-15
- [CVE-2026-94127](https://intel.threadlinqs.com/cve/CVE-2026-94127) — CRITICAL 9.8 · KEV · EPSS 1.4% · 2026-09-22
- [CVE-2026-42530](https://intel.threadlinqs.com/cve/CVE-2026-42530) — HIGH 8.1 · EPSS 2.4% · 2026-06-17
- [CVE-2026-42055](https://intel.threadlinqs.com/cve/CVE-2026-42055) — HIGH 8.1 · EPSS 1.8% · 2026-06-17
- [CVE-2026-42945](https://intel.threadlinqs.com/cve/CVE-2026-42945) — HIGH 8.1 · EPSS 0.9% · 2026-05-13
- [CVE-2026-11311](https://intel.threadlinqs.com/cve/CVE-2026-11311) — HIGH 8.1 · EPSS 0.6% · 2026-06-17
- [CVE-2026-50107](https://intel.threadlinqs.com/cve/CVE-2026-50107) — HIGH 8.1 · EPSS 0.5% · 2026-06-17
- [CVE-2026-9256](https://intel.threadlinqs.com/cve/CVE-2026-9256) — HIGH 8.1 · EPSS 0.2% · 2026-05-22
- [CVE-2026-42946](https://intel.threadlinqs.com/cve/CVE-2026-42946) — MEDIUM 6.5 · EPSS 0.1% · 2026-05-13
- [CVE-2026-40701](https://intel.threadlinqs.com/cve/CVE-2026-40701) — MEDIUM 4.8 · EPSS 0% · 2026-05-13

## Products affected

Threadlinqs normalises CPE and CNA product records across all 13 CVEs; 18 distinct F5 products are affected. The most frequently affected:

- NGINX Open Source — 6 CVEs
- NGINX Plus — 5 CVEs
- Big-ip Access Policy Manager — 3 CVEs
- BIG-IP — 2 CVEs
- NGINX Gateway Fabric — 2 CVEs
- Big-ip Advanced Firewall Manager — 1 CVE
- Big-ip Advanced Web Application Firewall — 1 CVE
- Big-ip Analytics — 1 CVE
- Big-ip Application Acceleration Manager — 1 CVE
- Big-ip Application Security Manager — 1 CVE
- Big-ip Ddos Hybrid Defender — 1 CVE
- Big-ip Domain Name System — 1 CVE
- Big-ip Fraud Protection Service — 1 CVE
- Big-ip Global Traffic Manager — 1 CVE
- Big-ip Link Controller — 1 CVE
- Big-ip Local Traffic Manager — 1 CVE
- Big-ip Policy Enforcement Manager — 1 CVE
- Ssl Orchestrator — 1 CVE

## Threat activity

22 tracked threat campaigns reference F5 products or exploit F5 CVEs:

- [CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud Orchestrator Auth Bypass, F5 BIG-IP APM Heap Overflow](https://intel.threadlinqs.com/threat/TL-2026-2678) — CRITICAL — 2026-09-26
- [Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS](https://intel.threadlinqs.com/threat/TL-2026-2660) — MEDIUM — 2026-09-24
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for Unauthenticated Remote Code Execution](https://intel.threadlinqs.com/threat/TL-2026-2632) — CRITICAL — 2026-09-23
- [F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)](https://intel.threadlinqs.com/threat/TL-2026-2596) — HIGH — 2026-09-21
- [Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via Bundled Fortinet NGFW < V7.4.3 (SSA-832273)](https://intel.threadlinqs.com/threat/TL-2026-2489) — CRITICAL — 2026-09-13
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked Actors](https://intel.threadlinqs.com/threat/TL-2026-2273) — HIGH — 2026-09-01
- [AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day (CVE-2026-63078)](https://intel.threadlinqs.com/threat/TL-2026-1961) — HIGH — 2026-08-09
- [Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1774) — MEDIUM — 2026-07-27
- [F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)](https://intel.threadlinqs.com/threat/TL-2026-1503) — HIGH — 2026-07-18
- [F5 Patches Multiple NGINX Vulnerabilities: Heap Overflow, Memory Disclosure, and Use-After-Free (CVE-2026-42533, CVE-2026-60005, CVE-2026-56434)](https://intel.threadlinqs.com/threat/TL-2026-1391) — CRITICAL — 2026-07-15
- [StrikeShark Campaign: SharkLoader Dropper Targets Governments and Software Developers via N-Day Exploits and Trojanized Installers to Deploy Cobalt Strike](https://intel.threadlinqs.com/threat/TL-2026-1237) — HIGH — 2026-07-11
- [SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt Strike](https://intel.threadlinqs.com/threat/TL-2026-1101) — HIGH — 2026-07-03
- [SharkLoader Malware Deploys Cobalt Strike Beacon via DLL Side-Loading in StrikeShark Campaign](https://intel.threadlinqs.com/threat/TL-2026-0961) — HIGH — 2026-06-27
- [F5 Out-of-Band Patches for Critical NGINX HTTP/3 Use-After-Free and Proxy/gRPC Heap Overflow (CVE-2026-42530, CVE-2026-42055) plus NGINX Gateway Fabric Config Injection (CVE-2026-11311, CVE-2026-50107)](https://intel.threadlinqs.com/threat/TL-2026-0848) — CRITICAL — 2026-06-18
- [Velvet Ant (Operation Highland): Backdoored Linux PAM and OpenSSH for ~Decade-Long Espionage Persistence](https://intel.threadlinqs.com/threat/TL-2026-0807) — CRITICAL — 2026-06-15
- [Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay (CVE-2025-33073, CVE-2025-53521)](https://intel.threadlinqs.com/threat/TL-2026-0596) — HIGH — 2026-05-26
- [F5 BIG-IP Edge Appliance Abused for SSH Pivot → Confluence RCE → CVE-2025-33073 Kerberos Relay to Active Directory (Microsoft Defender Research)](https://intel.threadlinqs.com/threat/TL-2026-0572) — HIGH — 2026-05-23
- [Nginx-poolslip CVE-2026-9256 — Pre-Auth Heap Buffer Overflow in NGINX ngx_http_rewrite_module (Patch Bypass of CVE-2026-42945 'NGINX Rift')](https://intel.threadlinqs.com/threat/TL-2026-0573) — CRITICAL — 2026-05-23
- [NGINX Rift — CVE-2026-42945 Heap Buffer Overflow in ngx_http_rewrite_module (CVSS v4 9.2 Critical, 18-Year-Old Pre-Auth RCE, Public PoC)](https://intel.threadlinqs.com/threat/TL-2026-0517) — CRITICAL — 2026-05-14
- [F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack Buffer Overflow (CVE-2025-53521) — CISA KEV Active Exploitation by Chinese Nation-State Actor](https://intel.threadlinqs.com/threat/TL-2026-0312) — CRITICAL — 2026-04-02
- [CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack-based Buffer Overflow](https://intel.threadlinqs.com/threat/TL-2026-0307) — CRITICAL — 2026-04-01
- [CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via apmd Process — Active Exploitation by UNC5221 (BRICKSTORM)](https://intel.threadlinqs.com/threat/TL-2026-0297) — CRITICAL — 2026-03-30

## Threat actors targeting F5

Named threat actors attributed to campaigns that involve F5 products or CVEs, with the number of linked campaigns:

- [UNC5221](https://intel.threadlinqs.com/actor/UNC5221) — 3 campaigns
- [UTA0178](https://intel.threadlinqs.com/actor/UTA0178) — 3 campaigns
- [StrikeShark](https://intel.threadlinqs.com/actor/StrikeShark) — 2 campaigns
- [Velvet Ant](https://intel.threadlinqs.com/actor/Velvet%20Ant) — 1 campaign

## How to prioritise F5 patching

This order follows the data Threadlinqs holds for F5, not a generic severity checklist:

- 5 of 13 F5 CVEs (38%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2020-5902](https://intel.threadlinqs.com/cve/CVE-2020-5902), [CVE-2023-44487](https://intel.threadlinqs.com/cve/CVE-2023-44487), [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747).
- 2 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2026-42530](https://intel.threadlinqs.com/cve/CVE-2026-42530) (2.4%), [CVE-2026-42055](https://intel.threadlinqs.com/cve/CVE-2026-42055) (1.8%), [CVE-2026-42945](https://intel.threadlinqs.com/cve/CVE-2026-42945) (0.9%).
- 4 CVEs score Critical and 7 High on CVSS v3 (maximum 9.8, average 8.2); sequence these after KEV and high-EPSS items.
- 6 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/f5
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
