logo

CERT-In Flags Critical F5 Security Flaws

ID: 297d56f7-156b-5f66-bc31-c497ec8396b3

STIX ID: report--297d56f7-156b-5f66-bc31-c497ec8396b3

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-10-17

Date Updated: 2026-07-16

...
...

CERT-In advisory CIVN-2025-0035 details multiple vulnerabilities affecting a broad range of F5 products (BIG-IP Next, BIG-IP 15/16/17, BIG-IQ, F5 Distributed Cloud, F5 Silverline, NGINX, Traffix, and hardware models), including CVEs in zlib, Apache Tomcat, MiniZip, and tcpdump that can enable denial-of-service, session hijacking, buffer overflows, and potential arbitrary code execution; F5 recommends mitigations such as disabling HTTP compression, restricting configuration access, upgrading affected components, and applying security patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.