Skip to content

ED 26-01, Mitigate Vulnerabilities in F5 Devices

In effectCISA · Emergency Directive · October 15, 2025

Summary

After a nation-state actor stole F5 BIG-IP source code and vulnerability details, required agencies to inventory F5 devices, check whether management interfaces face the internet, apply F5's October 2025 updates, disconnect end-of-support devices, and report to CISA.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
Emergency Directive
Number
ED 26-01
Issued
October 15, 2025
Status
In effect

Still in force, possibly with amendments.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.