logo

How to find F5 BIG-IP instances on your network

ID: 108b3c25-a098-5018-b1ca-60cd3a277d53

STIX ID: report--108b3c25-a098-5018-b1ca-60cd3a277d53

Feed Name: runZero Blog

Threat Score
90/100

Date Published: 2022-05-05

Date Updated: 2026-04-29

Author: runZero Team

...
...

CISA issued an emergency directive (Oct 15, 2025) after a nation-state affiliated actor compromised F5 BIG-IP systems and exfiltrated proprietary source code and vulnerability information; organizations are urged to inventory BIG-IP assets, assess public exposure, apply F5 vendor updates, and disconnect affected end-of-support devices. The report also reviews the May 2022 CVE-2022-1388 (CVSS 9.8), an unauthenticated iControl REST bypass that allowed full control of vulnerable BIG-IP management interfaces, and notes that patches and mitigations are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.