LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-22986: F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-22986 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system…

CVE-2021-22986 is a remote code execution vulnerability in the iControl REST interface of F5 BIG-IP and BIG-IQ Centralized Management. Unauthenticated attackers with network access can execute system commands, create or delete files, and disable services. It matters because these platforms often sit at the edge of networks controlling traffic and security policy; successful abuse can give an attacker deep control of critical infrastructure. Public reporting also links this issue to ransomware activity, raising the urgency of rapid response.

How it works

The weakness is classified as CWE-863 (Incorrect Authorization). In plain terms, the iControl REST interface fails to enforce proper authorization checks on certain requests. An attacker who can reach the interface over the network does not need valid credentials to invoke functionality that should be restricted. Once that barrier is bypassed, the attacker can run system-level commands, manipulate files, or shut down services on the device. Exact request formats and any preconditions must be confirmed against the vendor advisory; defenders should treat any unauthenticated reachability to iControl REST as high risk for this class of flaw.

Am I affected? How to find it in your systems

F5 BIG-IP appliances and virtual editions commonly terminate TLS, load-balance applications, or enforce access policy; BIG-IQ Centralized Management is used to administer fleets of those devices. Inventory every BIG-IP and BIG-IQ instance, including those in lab, DR, and cloud environments. Confirm the exact software versions and whether the iControl REST interface is enabled and reachable from untrusted networks; specifics on vulnerable builds must be checked against the vendor advisory.

Absence of obvious log entries does not prove safety; many exploitation attempts leave minimal traces if logging was not tuned for the interface.

How to remediate

Patch first. Apply the updates published by F5 for BIG-IP and BIG-IQ Centralized Management exactly as described in the vendor advisory. CISA’s required action is to apply those updates per vendor instructions. After patching, verify the interface is no longer vulnerable and that management access is restricted to authorized networks only.

If you can't patch immediately

Reduce the attack surface until the vendor update can be installed. Compensating controls for this class of unauthenticated management-plane RCE include:

These steps lower risk but do not eliminate it; treat them as temporary bridges to full patching.

If your data may have been exposed

Actively exploited vulnerabilities, especially those with known ransomware use, frequently lead to broader compromise and data theft. If you have evidence of exploitation or simply cannot rule it out, follow your incident-response plan: isolate affected devices, preserve logs and memory images, and engage forensic support. As one quick external check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public leaks.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedF5 · BIG-IP and BIG-IQ Centralized Management
WeaknessCWE-863
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities