F5 published product advisories covering two third-party software flaws affecting Apache Solr and Spring Cloud Gateway, identified as CVE-2026-22022 and CVE-2026-22750. The notices indicate that customers using F5 products with these components should review vendor guidance and determine whether their deployments are exposed through bundled or integrated software.
The advisories were released through F5's product security channel and point to separate vulnerability cases rather than a single defect. Organizations running F5 environments that rely on search or API gateway functionality should inventory affected instances, assess exposure, and prioritize remediation or compensating controls based on the presence of the vulnerable components.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
F5 issued a product advisory regarding Spring Cloud Gateway vulnerability CVE-2026-22750. The reference includes no synopsis or further details about impact or remediation.
F5 issued a product advisory بشأن Apache Solr vulnerability CVE-2026-22022. No additional synopsis or technical details were provided in the reference.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.