The current version of F5 BIG-IP is 21.1.0 (as of 05/05/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
- CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution VulnerabilityRansomware
9.8 critical · over the network, without login · CISA deadline was 17 Nov 21
- CVE-2020-5902F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution VulnerabilityRansomware
9.8 critical · over the network, without login · CISA deadline was 3 May 22
9.8 critical · over the network, without login · CISA deadline was 31 May 22
9.8 critical · over the network, without login · CISA deadline was 21 Nov 23
- CVE-2021-22991F5 BIG-IP Traffic Management Microkernel Buffer Overflow
9.8 critical · over the network, without login · CISA deadline was 1 Feb 22
- CVE-2025-53521F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
9.8 critical · over the network, without login · CISA deadline was 30 Mar
- CVE-2023-46748F5 BIG-IP Configuration Utility SQL Injection Vulnerability
8.8 high · over the network, with a basic account · CISA deadline was 21 Nov 23
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Internet Systems Consortium BIND: Mehrere Schwachstellen
WID-SEC-W-2026-2484 · 3 Sept
- Internet Systems Consortium BIND: Mehrere Schwachstellen
WID-SEC-W-2026-0863 · 3 Sept
- Red Hat Enterprise Linux (go-jose): Schwachstelle ermöglicht Denial of Service
WID-SEC-W-2026-1268 · 3 Sept
- Linux Kernel: Mehrere Schwachstellen
WID-SEC-W-2026-0861 · 3 Sept
- F5 BIG-IP: Mehrere Schwachstellen
WID-SEC-W-2026-3158 · 3 Sept
- PostgreSQL: Mehrere Schwachstellen
WID-SEC-W-2026-1544 · 2 Sept
- Red Hat Enterprise Linux (urllib3): Mehrere Schwachstellen ermöglichen Denial of Service
WID-SEC-W-2026-0207 · 2 Sept
- Apache HTTP Server: Mehrere Schwachstellen
WID-SEC-W-2025-1529 · 2 Sept
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 21.1LTS | 21.1.0 | EOL 5 May 29 |
| 21.0 | 21.0.0 | End of Life |
| 17.5LTS | 17.5.1 | EOL 1 Jan 29 |
| 17.1LTS | 17.1.3 | EOL 31 Mar 27 |
| 17.0 | 17.0.0 | End of Life |
| 16.1LTS | 16.1.6 | End of Life |
| 16.0 | 16.0.1.1 | End of Life |
| 15.1LTS | 15.1.10 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 21.1.0 | LTS | 05/05/2026 | – |
Frequently asked questions
- What is the latest version of F5 BIG-IP?
- F5 BIG-IP 21.1.0, released 05/05/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the F5 BIG-IP release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new F5 BIG-IP updates?
- Tick F5 BIG-IP off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new F5 BIG-IP version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The subscription is free and ends with one click.
Watch F5 BIG-IPEmbed this badge
The badge shows the current F5 BIG-IP version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/f5-big-ip)https://patchletter.com/badge/f5-big-ip.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).