CISA Emergency Directive 26-01: Mitigate Vulnerabilities in F5 Devices
- •F5 BIG-IP hardware devices
- •F5OS
- •BIG-IP TMOS
- •Virtual Edition
- •BIG-IP Next
- •BIG-IP IQ
- •BNK / CNF
Executive Summary
CISA issued Emergency Directive ED 26-01 directing Federal Civilian Executive Branch agencies to inventory F5 BIG-IP products, evaluate whether networked management interfaces are accessible from the public internet, and apply newly released F5 updates. A nation-state affiliated cyber threat actor has compromised F5 systems and exfiltrated data, including portions of the BIG-IP proprietary source code and vulnerability information, posing an imminent threat to networks using F5 devices and software.
Municipal Impact
While directed at federal agencies, municipal and SLTT organizations using F5 BIG-IP devices should apply the same inventory, hardening, patching, and disconnect actions to reduce exposure.
SMB Impact
Small and medium businesses running F5 BIG-IP or F5OS products should apply the latest F5 updates, restrict management interface exposure, and disconnect end-of-support devices.
Recommended Actions
- Inventory all instances of F5 BIG-IP hardware devices and F5OS, BIG-IP TMOS, Virtual Edition, BIG-IP Next, BIG-IP IQ, and BNK/CNF software.
- Harden public-facing hardware and software appliances; identify whether public internet access to the networked management interface exists.
- Apply the latest F5 vendor updates by October 22, 2025 for F5OS, BIG-IP TMOS, BIG-IQ, and BNK/CNF (validating F5 MD5 checksums), and by October 31, 2025 for other devices.
- Disconnect public-facing F5 devices that have reached end-of-support.
- Follow CISA guidance on BIG-IP cookie leakage mitigation and report inventories/actions to CISA by October 29, 2025.
Grey Matter Analysis
References
- https://www.cisa.gov/news-events/directives/ed-26-01-mitigate-vulnerabilities-f5-devices
- https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fmy.f5.com%2fmanage%2fs%2farticle%2fK000156572&c=E,1,qkkJ8wbDPx5idaJcOqf02XgqDyh5nD9wZFTO1LucvcmjES4hiO233wYd5NQELDKJQrtamttzzMZWJZv31-TzwlC4d1A5CeXzdbBKUkOk&typo=1
Tags
Related Intelligence
Need help with this advisory?
Contact Grey Matter to assess your exposure and prioritize remediation.
Contact Grey Matter