// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
Breach Record

F5

DISCLOSED 2026-05-22 · UNKNOWN

A threat actor compromised an end-of-life F5 BIG-IP edge appliance and pivoted to an internal Linux host via SSH. From there, they exploited an unpatched Atlassian Confluence server to gain code execution and used relay-style authentication attacks against Active Directory. The incident highlights risks from unpatched edge devices and SaaS applications enabling lateral...

The record

What we know

Disclosed
2026-05-22
Sources

Cited reporting

This page is the permanent ColdRecon entry for the F5 disclosure. It updates if new public reporting emerges. All tracked breaches →

F5 just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →