F5 Released Security Updates Covering Multiple Products Following Recent Hack
F5 Networks has issued critical security updates in response to a security breach involving a nation-state threat actor. The breach, detected in August 2025, resulted in unauthorized access to internal systems and the theft of BIG-IP source code and…
F5 Networks has issued critical security updates in response to a security breach involving a nation-state threat actor. The breach, detected in August 2025, resulted in unauthorized access to internal systems and the theft of BIG-IP source code and vulnerability data.
The breach was identified on August 9, 2025, when F5 detected suspicious activity within its BIG-IP product development environment. The threat actor maintained persistent access, exfiltrating sensitive files, including portions of source code and configuration details for a limited number of customers. No evidence suggests alterations to the software supply chain or impacts on production systems. However, the stolen intellectual property raises concerns about potential zero-day exploits targeting unpatched deployments.
F5 has implemented patches across BIG-IP, F5OS, BIG-IQ, APM clients, and BIG-IP Next for Kubernetes to protect customers. The company engaged cybersecurity firms CrowdStrike and Mandiant for investigation support and collaborated with law enforcement and government agencies. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive ED 26-01, requiring federal agencies to patch and isolate affected F5 assets immediately.
On October 15, 2025, F5 released its Quarterly Security Notification, addressing 44 vulnerabilities, many linked to the breach. High-severity CVEs, with scores up to 8.7 under CVSS v3.1, affect components like SCP/SFTP in BIG-IP (CVE-2025-53868) and F5OS platforms (CVE-2025-61955). These flaws can lead to denial-of-service, privilege escalation, and remote code execution, especially in appliance modes.
CVE ID CVSS Score (v3.1 / v4.0) Affected Products Affected Versions Fixes Introduced In
CVE-2025-53868 8.7 / 8.5 BIG-IP (all modules) 17.5.0, 17.1.0-17.1.2, 16.1.0-16.1.6, 15.1.0-15.1.10 17.5.1, 17.1.3, 16.1.6.1, 15.1.10.8
F5 Networks has issued critical security updates in response to a security breach involving a nation-state threat actor.
CVE-2025-61955 7.8 (standard) / 8.8 (appliance) / 8.5 F5OS-A, F5OS-C F5OS-A: 1.8.0^3, 1.5.1-1.5.3; F5OS-C: 1.8.0-1.8.1, 1.6.0-1.6.2^3 F5OS-A: 1.8.3, 1.5.4; F5OS-C: 1.8.2, 1.6.4
CVE ID CVSS Score (v3.1 / v4.0) Affected Products Affected Versions Fixes Introduced In
CVE-2025-59481 6.5 (standard) / 8.7 (appliance) / 8.5 BIG-IP (all modules) 17.5.0-17.5.1, 17.1.0-17.1.2, 16.1.0-16.1.6, 15.1.0-15.1.10 17.5.1.3, 17.1.3, 16.1.6.1, 15.1.10.8
CVE ID CVSS Score (v3.1 / v4.0) Affected Products Affected Versions Fixes Introduced In
CVE-2025-58424 3.7 / 6.3 BIG-IP (all modules), F5 Silverline (all services) BIG-IP: 17.1.0-17.1.2, 16.1.0-16.1.5, 15.1.0-15.1.10; Silverline: N/A BIG-IP: 17.1.2.2^3, 16.1.6^3, 15.1.10.8^3; Silverline: N/A
Exposure ID Affected Products Affected Versions Fixes Introduced In
K000150010: BIG-IP AFM security exposure BIG-IP AFM 17.5.0-17.5.1, 17.1.0-17.1.2, 16.1.0-16.1.6, 15.1.0-15.1.10 17.5.1.1, 17.1.3
F5 emphasizes the necessity of applying these updates promptly to avoid potential lateral movement and data exfiltration in customer networks. Decommissioning end-of-life products further reduces exposure. Organizations are encouraged to enable event streaming to SIEM tools and isolate management interfaces from public access.
For comprehensive details, refer to F5’s official notification.
Based on reporting by Cyber Security News.
