CVE-2025-53868
published 2025-10-15CVE-2025-53868: When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictions using…
PriorityP351high8.7CVSS 3.1
AVNACLPRHUINSCCHIHAN
EPSS
0.42%
34.0th percentile
When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictions using undisclosed commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
108 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip | >= 17.1.0 < 17.1.3.1 | 17.1.3.1 |
| f5 | big-ip | >= 17.5.0 < 17.5.1 | 17.5.1 |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip_access_policy_manager | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip_access_policy_manager | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip_access_policy_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip_advanced_firewall_manager | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip_advanced_firewall_manager | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip_advanced_firewall_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip_advanced_web_application_firewall | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip_advanced_web_application_firewall | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip_advanced_web_application_firewall | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | >= 15.1.0 < 15.1.10.8 | 15.1.10.8 |
| f5 | big-ip_analytics | >= 16.1.0 < 16.1.6.1 | 16.1.6.1 |
| f5 | big-ip_analytics | >= 17.1.0 < 17.1.3 | 17.1.3 |
| f5 | big-ip_analytics | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_apm | — | — |
CVSS provenance
nvdv3.18.7HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
nvdv4.08.5HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p36j-q4xc-rcrv: When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictio
ghsa_unreviewed·2025-10-15
CVE-2025-53868 [HIGH] CWE-78 GHSA-p36j-q4xc-rcrv: When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictio
When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictions using undisclosed commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5
CVE-2025-53868: When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to...
vendor_f5·2025-10-15·CVSS 8.7
CVE-2025-53868 [HIGH] CWE-78 CVE-2025-53868: When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to...
CVE-2025-53868: When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to...
When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictions using undisclosed commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP AVR, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP CGNAT, BIG-IP DHD, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP SSLO, BIG-IP WebAccelerator, BIG-IP WebSafe, Big-Ip Automation Toolchain, Big-Ip Container Ingress Services
Affected Versions: 15.
No detection rules found.
No public exploits indexed.
Qualys
A Strategic Response to the F5 BIG-IP Nation-State Breach 2025
blogs_qualys·2025-10-18
A Strategic Response to the F5 BIG-IP Nation-State Breach 2025
## Table of Contents
CISAs KEV Inclusion Underscores the Severity of the F5 BIG-IP Breach
The Risk-Velocity Mismatch: F5 Patching Decelerates as Attacker Insight Accelerates
How Qualys Helps You Discover F5 Assets and Detect Related Vulnerabilities
Conclusion
In mid-October 2025, the cybersecurity landscape was dealt a severe blow. F5 disclosed a long-term, sophisticated breach by a nation-state threat actor. This incident exposed critical F5 BIG-IP vulnerabilities and triggered heightened scrutiny across enterprise edge infrastructure.
This was not a typical vulnerability disclosure. The attackers exfiltrated a strategic critical pair of assets: portions of BIG-IP source code, and internal details of undisclosed (unpatched) vulnerabilities.
## CISA’s KEV Inclusion Underscores the S
Qualys
F5 BIG-IP Vulnerabilities: Strategic Breach Response with Qualys | Qualys
blogs_qualys·2025-10-18
F5 BIG-IP Vulnerabilities: Strategic Breach Response with Qualys | Qualys
#### Table of Contents
- CISAs KEV Inclusion Underscores the Severity of the F5 BIG-IP Breach
- The Risk-Velocity Mismatch: F5 Patching Decelerates as Attacker Insight Accelerates
- How Qualys Helps You Discover F5 Assets and Detect Related Vulnerabilities
- Conclusion
In mid-October 2025, the cybersecurity landscape was dealt a severe blow. F5 disclosed a long-term, sophisticated breach by a nation-state threat actor. This incident exposed critical F5 BIG-IP vulnerabilities and triggered heightened scrutiny across enterprise edge infrastructure.
This was not a typical vulnerability disclosure. The attackers exfiltrated a strategic critical pair of assets: portions of BIG-IP source code, and internal details of undisclosed (unpatched) vulnerabilities.
## CISA’s KEV Inclusion Underscore
Unit42
Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
blogs_unit42·2025-10-16·CVSS 8.5
CVE-2025-53868 [HIGH] Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
Justin Moore
Published: October 16, 2025
High Profile Threats
Vulnerabilities
CVE-2025-53868
CVE-2025-57780
CVE-2025-61955
Exfiltration
## Executive Summary
On Oct. 15, 2025, F5 — a U.S. technology company — disclosed that a nation-state threat actor conducted a significant long-term compromise of their corporate networks. In this incident, attackers stole source code from their BIG-IP suite of products and information about undisclosed vulnerabilities. F5’s BIG-IP suite is commonly used by large organizations, primarily in the U.S. but also globally, for availability, access control and security. Organizations including gove
Unit42
Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
blogs_unit42·2025-10-16·CVSS 8.5
[HIGH] Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
## Executive Summary
On Oct. 15, 2025, F5 — a U.S. technology company — disclosed that a nation-state threat actor conducted a significant long-term compromise of their corporate networks. In this incident, attackers stole source code from their BIG-IP suite of products and information about undisclosed vulnerabilities. F5’s BIG-IP suite is commonly used by large organizations, primarily in the U.S. but also globally, for availability, access control and security. Organizations including government agencies and Fortune 500 companies rely on BIG-IP.
Cortex Xpanse currently identifies over 600,000 unique hosts behind a Big-IP instance exposed to the internet.
F5’s investigation revealed that the attackers maintained long-term access to the company’s product development environment and eng
Tenable
FAQ on F5 Security Incident
blogs_tenable·2025-10-15
FAQ on F5 Security Incident
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Unit42
Threat Brief: Twelve Tips for the Holidays
blogs_unit42·2018-12-13
Threat Brief: Twelve Tips for the Holidays
## Threat Brief: Twelve Tips for the Holidays
Unit 42
Published: December 13, 2018
High Profile Threats
Learning Hub
Devices
Holidays
Home security
IoT
Privacy
This time every year, people all over the world get new devices. Regardless of what holiday(s) you may (or may not) celebrate, the end of the year is a time for people to give and receive some of the latest devices to come on to the market.
Nothing spoils a new gadget more than having some kind of security or privacy problem related to it. After that, nothing spoils the fun and excitement of unboxing and playing with an exciting new device than trying to figure out what you need to do to use it with reasonable safety and privacy.
To that end, we’re providing some very basic, but critical steps that you, your family, you
Unit42
Threat Brief: Embrace Mobile Banking with Caution
blogs_unit42·2018-10-23
Threat Brief: Embrace Mobile Banking with Caution
## Threat Brief: Embrace Mobile Banking with Caution
Unit 42
Published: October 23, 2018
High Profile Threats
Learning Hub
Banking
Banking trojans
Mobile
Online banking
The Brazilian Central Bank recently announced that 2017 was the first year in which people did more banking using mobile devices than on PCs. There were 24.5 billion mobile banking transactions while there were 20.6 billion PC-based transactions.
Not all countries are embracing mobile banking as quickly as Brazil. But, mobile banking use is picking up around the globe.
What is it?
As more people move to mobile banking, we believe attackers will focus their attacks away from PC banking and towards mobile banking. This means the risks of losing control of your accounts through mobile online banking are likely to
2025-10-15
Published