Story perspectives
Federal Agencies Ordered to Patch Critical F5 Vulnerabilities
10/17/2025
1 of 2
Story summary
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 26-01 to require federal agencies to patch F5 vulnerabilities.
- A nation-state actor accessed sensitive files, including the BIG-IP source code.
- The breach prompted agencies to apply updates by October 22, 2025.
- Federal agencies must submit inventory reports by October 29, 2025.
- CISA remains operational during the government shutdown, noting the threat extends to private sector F5 users.
1 / 2
