CVE-2021-22986: listed in the CISA KEV catalog CVE-2021-22986 · CVSS 9.8 CRITICAL · EPSS 99.9% · KEV 2021-11-03 · patch available
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Is CVE-2021-22986 exploited? Listed in the CISA KEV catalog on 2021-11-03. Federal remediation due 2021-11-17. Past that date by 1779 days. Used in ransomware campaigns. EPSS puts exploitation in the next 30 days at 99.9%. Public exploit code: packaged in a public tool. Public detection rules exist. Which products and versions are affected? BIG-IP; BIG-IQ · BIG-IP 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, BIG-IQ 7.1.0.x before 7.1.0.3, 7.0.0.x before 7.0.0.2 f5 · big-ip access policy manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip advanced firewall manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip advanced web application firewall · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip analytics · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip application acceleration manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip application security manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip ddos hybrid defender · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip domain name system · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip fraud protection service · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip global traffic manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip link controller · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip local traffic manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip policy enforcement manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-iq centralized management · >= 6.0.0, < 6.1.0, >= 7.0.0, < 7.0.0.2, >= 7.1.0, < 7.1.0.3 f5 · ssl orchestrator · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 Is there a patch? big-ip access policy manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip advanced firewall manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip advanced web application firewall 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip analytics 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip application acceleration manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip application security manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip ddos hybrid defender 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip domain name system 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip fraud protection service 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip global traffic manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip link controller 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip local traffic manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip policy enforcement manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-iq centralized management 6.1.0, 7.0.0.2, 7.1.0.3 ssl orchestrator 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more What PlainSec published about CVE-2021-22986 Primary sources KEV and EPSS are re-checked daily. Record last updated 2026-09-15.
CVE-2021-22986: listed in the CISA KEV catalog CVE-2021-22986 · CVSS 9.8 CRITICAL · EPSS 99.9% · KEV 2021-11-03 · patch available
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Is CVE-2021-22986 exploited? Listed in the CISA KEV catalog on 2021-11-03. Federal remediation due 2021-11-17. Past that date by 1779 days. Used in ransomware campaigns. EPSS puts exploitation in the next 30 days at 99.9%. Public exploit code: packaged in a public tool. Public detection rules exist. Which products and versions are affected? BIG-IP; BIG-IQ · BIG-IP 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, BIG-IQ 7.1.0.x before 7.1.0.3, 7.0.0.x before 7.0.0.2 f5 · big-ip access policy manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip advanced firewall manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip advanced web application firewall · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip analytics · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip application acceleration manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip application security manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip ddos hybrid defender · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip domain name system · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip fraud protection service · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip global traffic manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip link controller · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip local traffic manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip policy enforcement manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-iq centralized management · >= 6.0.0, < 6.1.0, >= 7.0.0, < 7.0.0.2, >= 7.1.0, < 7.1.0.3 f5 · ssl orchestrator · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 Is there a patch? big-ip access policy manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip advanced firewall manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip advanced web application firewall 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip analytics 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip application acceleration manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip application security manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip ddos hybrid defender 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip domain name system 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip fraud protection service 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip global traffic manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip link controller 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip local traffic manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip policy enforcement manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-iq centralized management 6.1.0, 7.0.0.2, 7.1.0.3 ssl orchestrator 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more What PlainSec published about CVE-2021-22986 Primary sources KEV and EPSS are re-checked daily. Record last updated 2026-09-15.