Actively exploited
Listed in CISA’s Known Exploited Vulnerabilities catalog since November 3, 2021.
CVE-2021-22986
F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
F5 · BIG-IP and BIG-IQ Centralized Management
Added to KEV November 3, 2021
Alert details
- Source feed
- CISA KEV
- CVE ID
- CVE-2021-22986
- CWE
- CWE-863
- Affected products
- BIG-IP and BIG-IQ Centralized Management · F5 BIG-IP and BIG-IQ Centralized Management · F5
What happened
F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.
What it means for your business
F5 BIG-IP and BIG-IQ Centralized Management is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-22986). F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
Required action
Apply updates per vendor instructions.
CISA due date: November 17, 2021
Sources
Related briefs
Microsoft PowerShell Security Feature Bypass vulnerability
Microsoft PowerShell Security Feature Bypass vulnerability (CVE-2026-70338) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Cross Device Service Elevation of Privilege vulnerability
Microsoft Windows Cross Device Service Elevation of Privilege vulnerability (CVE-2026-66804) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows iSCSI Target Service Remote Code Execution vulnerability
Windows iSCSI Target Service Remote Code Execution vulnerability (CVE-2026-65791) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Apple macOS Improper Authentication Vulnerability
Apple macOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-65400). Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. CISA remediation due date: 2026-08-21. If you need help checking exposure, call (864) 335-9223.
Need help patching?
PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.