CISA issued Emergency Directive 26-01 in mid-October 2025 after F5 disclosed that an actor had long-term access to its systems and stole portions of BIG-IP source code and undisclosed vulnerability data. Agencies were ordered to inventory F5 products, pull management interfaces off the public internet, and patch inside a week. The next day the American Hospital Association told hospitals to do the same, its cybersecurity advisor noting F5 gear is ubiquitous across the health field.

This was not a bug in a device. It was a breach of the vendor that makes the load balancer in front of the device, and the stolen vulnerability research is a preview of exploits that had not shipped yet.

Supply-chain compromise keeps moving up a layer. Your threat model has to include the security of the companies whose code and appliances you depend on, because their breach becomes your incident on someone else timeline.