logo

RIFT: Detection capabilities for recent F5 BIG-IP/BIG-IQ iControl REST API vulnerabilities CVE-2021-22986

ID: 83271498-57fa-5924-9dcd-f6c40efb3843

STIX ID: report--83271498-57fa-5924-9dcd-f6c40efb3843

Feed Name: NCC Research

Threat Score
85/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

ADMIRALTY:B6
...
...

**Executive summary:** NCC Group observed active exploitation attempts against F5 BIG‑IP/BIG‑IQ iControl REST API vulnerabilities (CVE-2021-22986 and related CVEs), reproduced the SSRF-based authentication bypass that leads to authenticated remote code execution via the tm/util/bash endpoint, published log and network detection artifacts (restjavad, restjavad-audit, audit entries) and Suricata rules, and noted the release of a public exploit—recommend immediate monitoring, relevant log inspection, and patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.