← Intelligence Center

CISA Emergency Directive 26-01: Mitigate Vulnerabilities in F5 Devices

PublishedOct 15, 2025
Updated
VendorF5
SeverityHigh
Known ExploitedYes Known Exploited
Advisory IDINTEL-000018
CVEs
None identified.
Products
  • F5 BIG-IP hardware devices
  • F5OS
  • BIG-IP TMOS
  • Virtual Edition
  • BIG-IP Next
  • BIG-IP IQ
  • BNK / CNF

Executive Summary

CISA issued Emergency Directive ED 26-01 directing Federal Civilian Executive Branch agencies to inventory F5 BIG-IP products, evaluate whether networked management interfaces are accessible from the public internet, and apply newly released F5 updates. A nation-state affiliated cyber threat actor has compromised F5 systems and exfiltrated data, including portions of the BIG-IP proprietary source code and vulnerability information, posing an imminent threat to networks using F5 devices and software.

Municipal Impact

While directed at federal agencies, municipal and SLTT organizations using F5 BIG-IP devices should apply the same inventory, hardening, patching, and disconnect actions to reduce exposure.

SMB Impact

Small and medium businesses running F5 BIG-IP or F5OS products should apply the latest F5 updates, restrict management interface exposure, and disconnect end-of-support devices.

Recommended Actions

  1. Inventory all instances of F5 BIG-IP hardware devices and F5OS, BIG-IP TMOS, Virtual Edition, BIG-IP Next, BIG-IP IQ, and BNK/CNF software.
  2. Harden public-facing hardware and software appliances; identify whether public internet access to the networked management interface exists.
  3. Apply the latest F5 vendor updates by October 22, 2025 for F5OS, BIG-IP TMOS, BIG-IQ, and BNK/CNF (validating F5 MD5 checksums), and by October 31, 2025 for other devices.
  4. Disconnect public-facing F5 devices that have reached end-of-support.
  5. Follow CISA guidance on BIG-IP cookie leakage mitigation and report inventories/actions to CISA by October 29, 2025.

Grey Matter Analysis

Analysis pending review.

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter