Skip to content
COOEY

FAIL › dossier

F5

VENDOR

· dossier confidence 40%

F5 Networks, a leading provider of application security and delivery solutions, has a concerning history of critical security vulnerabilities, including remote code execution and SQL injection flaws, some of which have been actively exploited. A recent breach involving stolen source code and internal vulnerability data prompted a federal response, highlighting the need for improved security practices.

PROFILE
CategoryCybersecurityWhat they doF5 Networks provides application security and delivery solutions, including load balancing, web application firewalls, and security automation. They specialize in protecting and optimizing digital experiences.OwnershipPublic Websitehttps://www.f5.com/ ↗
SECURITY POSTURE

F5 has a history of critical remote code execution vulnerabilities, indicating a significant challenge in secure software development and vulnerability management. Their products have been actively exploited in ransomware attacks and a stolen vulnerability breach required a federal response.

Notable failures
  • CVE-2020-5902 (RCE)
  • CVE-2021-22986 (RCE)
  • CVE-2025-53521 (RCE)
  • CVE-2023-46747 (RCE)
  • CVE-2022-1388 (RCE, ransomware exploitation)
  • CVE-2023-46748 (SQL injection)
Patterns: Recurring critical remote code execution vulnerabilities; Authentication bypass vulnerabilities; Vulnerabilities in iControl REST interface; SQL injection vulnerabilities
FAILURE HISTORY · 9
DATEEVENTSEVSUMMARY
2026-03-27 CVE-2025-53521 high F5 BIG-IP APM stack-based buffer overflow enables remote code execution and is actively exploited in the wild.
2023-10-31 CVE-2023-46747 critical An unauthenticated attacker can bypass BIG-IP Configuration Utility authentication to execute system commands.
2022-01-18 CVE-2021-22991 high F5 BIG-IP Traffic Management Microkernel buffer overflow bypassed URL access controls and was actively exploited in the wild.
2023-10-31 CVE-2023-46748 high F5 BIG-IP Config Utility SQL Injection Vulnerability
2022-05-10 CVE-2022-1388 critical F5 BIG-IP's missing authentication allowed remote code execution and service disruption, actively exploited in ransomware attacks.
2021-11-03 CVE-2020-5902 critical F5 BIG-IP's TMUI had a critical, actively exploited remote code execution vulnerability in undisclosed pages.
2021-11-03 CVE-2021-22986 critical F5 BIG-IP devices had a critical, unauthenticated remote code execution vulnerability actively exploited by ransomware actors, allowing attackers to execute arbitrary commands on affected systems.
2026-05-19 CVE-2026-8711 high CVE-2026-8711: NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is config
2021-09-16 CVE-2021-40438 critical CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
cooey ↗severe-fallout-0.70
"…"
cooey ↗severe-fallout-1.00
negative
"…"
Open questions: What is F5's headquarters location? · What is F5's current employee count? · What is the nature of the stolen source code and vulnerability data breach? · What specific U.S. agencies were impacted by the stolen vulnerability data?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-19 05:07:05.931611+00:00