← Vulnerability feed

Vulnerability record · CVE-2021-22986 · published 31 March 2021

CVE-2021-22986: F5 BIG-IP iControl REST unauthenticated remote command execution

F5 · Big Ip Access Policy Manager

The iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 server-side request forgery. Because the interface is reachable without credentials and the flaw yields full command execution, it is a severe risk to any internet-exposed management plane. The record does not detail the internal mechanism beyond the SSRF classification.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-918 · Server-side request forgery (SSRF)
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
15Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with CVSS 9.8, KEV listing with known ransomware use, and near-maximum EPSS probability make this an urgent patch-or-isolate case.

What it is

The iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 server-side request forgery. Because the interface is reachable without credentials and the flaw yields full command execution, it is a severe risk to any internet-exposed management plane. The record does not detail the internal mechanism beyond the SSRF classification.

Impact

An unauthenticated attacker can execute arbitrary commands on the affected device, gaining full control of the appliance and its traffic-handling and management functions. This can lead to configuration theft, traffic interception, and use of the device as a foothold into the internal network.

Attack surface

Reached over the network via the iControl REST interface (CVSS vector AV:N/PR:N/UI:N), so no authentication and no user interaction are required. Any deployment exposing the management interface to untrusted networks is directly reachable.

Exploitation

CISA added it to the KEV catalog on 2021-11-03 with a 2021-11-17 due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99898 (99.9th percentile), and multiple references carry the Exploit tag, indicating public exploit code exists.

What to do

  • Apply the F5 vendor updates listed in advisory K03009991 for BIG-IP and BIG-IQ; upgrade to a fixed release for your branch.
  • Restrict access to the iControl REST interface so it is not reachable from untrusted networks; place management access behind a management VLAN, VPN, or allowlisted jump hosts.
  • Disable or block external exposure of the management interface and self-IPs where the REST service listens.
  • Monitor F5 security advisories for updated guidance and re-check any end-of-software-development versions that were not evaluated.
  • If immediate patching is not possible, apply network-level controls and increase monitoring of the management interface as a compensating measure.

Detection

  • Hunt for unexpected or anomalous requests to the iControl REST endpoints on BIG-IP/BIG-IQ management interfaces, especially from external or non-management source IPs.
  • Review appliance and web/proxy logs for command execution artifacts or unusual child processes spawned by the REST service.
  • Alert on new or modified administrative accounts, tokens, or configuration changes on BIG-IP/BIG-IQ devices.
  • Correlate management-interface access with threat intelligence for known exploitation of CVE-2021-22986.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-22986 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22986 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46747F5 BIG-IP configuration utility authentication bypass allows command executionUndisclosed requests can bypass authentication in the BIG-IP configuration utility, letting a network-positioned attacker execute arbitrary system co…KEVEPSS 97%analysed9.8CVE-2022-1388F5 BIG-IP iControl REST authentication bypassUndisclosed requests to the iControl REST interface on multiple F5 BIG-IP modules can bypass authentication, allowing an unauthenticated remote attac…KEVEPSS 100%analysed9.8CVE-2021-22991F5 BIG-IP TMM URI normalization buffer overflowF5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overf…KEVEPSS 61%analysed9.8CVE-2020-5902F5 BIG-IP TMUI path traversal leading to remote code executionThe F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed …KEVEPSS 100%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.3CVE-2026-94127F5 big-ip access policy manager heap-based buffer overflow vulnerabilityWhen a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution…KEVEPSS 2.2%9.3CVE-2025-53521F5 BIG-IP APM stack buffer overflow allows remote code executionA stack-based buffer overflow (CWE-121) exists in F5 BIG-IP Access Policy Manager when an APM access policy is configured on a virtual server. Specif…KEVEPSS 2.3%analysed

Source: NIST National Vulnerability Database (record CVE-2021-22986), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.