November 3, 2021 · Applied Cybernetics Group
CVE-2021-22986 — F5 BIG-IP and BIG-IQ Centralized Management
known ransomware use
F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
- Added to KEV
2021-11-03- Federal due date
2021-11-17- Vendor
- F5
- Product
- BIG-IP and BIG-IQ Centralized Management
- EPSS
- 100.0th percentile (score 0.945, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-22986
CISA short description
F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.
Required action
Apply updates per vendor instructions.