First published: 16 Oct 2025
Last updated: 16 Oct 2025

Content written for

Small & medium business
Large organisations & infrastructure
Government

This alert is intended for network and infrastructure teams, SOC analysts, and system administrators managing F5 products.

Background

F5 have released an advisory regarding a cyber security incident that has affected certain F5 systems with recommendation on what customers can do to help protect themselves.

In addition to this advisory, F5 has issued its October 2025 quarterly security notification summarising multiple critical vulnerabilities identified across its product portfolio. The notification details newly discovered and previously unresolved issues affecting multiple F5 platforms. The advisory provides a coordinated patch release to help customers maintain secure and supported versions across all F5 environments.

Mitigation advice

Organisations operating F5 BIG-IP, BIG-IP Next, F5OS-A/C, or Silverline devices running versions listed in the advisory. Affected builds include major releases 15.x through 17.x, as well as Next SPK, CNF, and Kubernetes versions.

ASD’s ACSC recommends affected organisations:

Monitor for updates and subscribe to F5 security advisories.

Where to get help

Organisations that have been impacted, suspect impact or require advice and assistance can contact us via 1300 CYBER1 (1300 292 371).

Was this helpful?
Yes this was helpful
No this was not helpful

Thanks for your feedback!

We welcome additional feedback below.

Was this information easy to understand?
Will you take action after reading this?
Did you find the information you were looking for?
Did the design and layout of this page meet your expectations?