F5 Networks has issued a series of security advisories addressing recently disclosed vulnerabilities in various third-party software components, including LibTIFF, GnuTLS, Samba, SQLite, Apache HTTP Server, gnuplot, and the Linux kernel (brcmfmac). Each advisory provides a technical summary of the vulnerability, its potential impact, and the results of F5's internal evaluation regarding exposure in their products. In all cases except for the SQLite vulnerability (CVE-2019-8457), F5 confirmed that their products are not affected and no action is required for customers using supported versions.
The SQLite advisory (CVE-2019-8457) details a heap out-of-bounds read issue that could allow a remote, low-privileged user to crash the system by providing a maliciously crafted R-Tree table. F5 has assigned internal tracking IDs and provided guidance for customers to determine if their products are affected, including references to diagnostic tools and remediation steps. These advisories reflect F5's ongoing process of evaluating and communicating the impact of upstream vulnerabilities on their product portfolio, ensuring customers are informed about potential risks and mitigations.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
F5 published product advisory K000158069 covering LibTIFF vulnerability CVE-2023-6277.
F5 published multiple product advisories covering Apache HTTP Server CVE-2024-47252/CVE-2025-49812, Samba CVE-2025-9640, GnuTLS CVE-2024-0567, SQLite CVE-2019-8457, and LibTIFF CVE-2023-52356.
F5 published product advisories K000158030 and K000158037 covering gnuplot CVE-2020-25969 and Linux kernel brcmfmac CVE-2022-50408.
An F5 product advisory references Samba vulnerability CVE-2025-9640 as a distinct tracked security issue.
An F5 product advisory references two Apache HTTP Server vulnerabilities, CVE-2024-47252 and CVE-2025-49812, as affecting relevant software components.
An F5 product advisory references GnuTLS vulnerability CVE-2024-0567 as a tracked security issue relevant to affected products.
An F5 product advisory references LibTIFF vulnerability CVE-2023-6277 as another separate tracked flaw in the library.
An F5 product advisory references LibTIFF vulnerability CVE-2023-52356 as a distinct security issue affecting the image-processing library.
An F5 product advisory references Linux kernel brcmfmac vulnerability CVE-2022-50408, marking it as a tracked issue for impacted environments.
An F5 product advisory references gnuplot vulnerability CVE-2020-25969 as a distinct tracked security issue relevant to affected products or components.
An F5 product advisory references SQLite vulnerability CVE-2019-8457, indicating this flaw as a tracked security issue affecting software components used in F5-related products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
my.f5.com
Open sourcemy.f5.com
Open sourcemy.f5.com
Open sourcemy.f5.com
Open sourcemy.f5.com
Open sourcemy.f5.com
Open sourcemy.f5.com
Open sourcemy.f5.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.