https://my.f5.com/manage/s/article/K000154696

These files contained some of our BIG-IP source code and information about undisclosed vulnerabilities we were working on in BIG-IP.

myF5

https://my.f5.com/manage/s/article/K000157005

In October 2025, F5 rotated its signing certificates and keys used to cryptographically sign F5-produced digital objects.

myF5

@wdormann also does not mention nginx app_protect module... which is derived from big-ip. so... great...
@wdormann So they where sitting on vulnerabilities without fixing them and the source code leak forced them to release the fix? Sounds about right.