Questions Regarding F5 Hardened Releases

Hi Team,

I have a few questions regarding F5 Hardened Releases (HR):

  1. CVE availability: After a Hardened Release has been available for more than six weeks, can we assume that no CVEs will be published later for that release? Or can security vulnerabilities/CVEs still be disclosed after this period?
  2. Upgrade priority: Are all Hardened Releases considered mandatory/high-priority releases, and should we plan to upgrade to the latest HR whenever one becomes available?
  3. HR versioning: Will Hardened Releases always follow a naming convention such as HR1, HR2, HR3, etc.?
  4. Upgrade path: If we are currently running the base version, can we directly upgrade to the latest Hardened Release? Or is there a specific upgrade path that must be followed (for example, Base → HR1 → HR2 → latest HR)?

Any clarification on the above would be greatly appreciated.

Thanks in advance.

Your F5 account team may be able to provide an answer faster and more complete than DevCentral.

Hi @gokulakrishnan1231

Thanks for reaching out! Here is the clarification regarding F5 Hardened Releases (HR):

  1. CVE Disclosures & Security Advisories:
    You should not assume that vulnerabilities will never be disclosed after a specific window. F5’s primary focus with Hardened Releases is proactive protection—delivering fixes into production software as quickly as possible. Disclosures or advisories may occur according to coordinated-disclosure standards and regulatory requirements.

  2. Upgrade Priority:
    Yes. F5 strongly recommends treating all Hardened Releases as high-priority updates. In the current threat landscape, security hygiene is paramount, and applying these proactive fixes ensures your fleet is protected against emerging threats and potential exploit chains.

  3. Versioning & Naming Conventions:
    The naming convention depends on the platform:

    • BIG-IP: These updates are integrated as standard 4-digit maintenance/point releases (for example, 17.1.3.4, 17.5.1.8, etc.).
    • F5OS: These releases typically use the explicit HR designation in the package name (for example, F5OS-C 1.8.3 HR1).
  4. Upgrade Paths (Direct Upgrade):
    Yes, you can upgrade directly from your current base version to the latest Hardened Release. These releases are cumulative, meaning the latest update contains all preceding security fixes and protections. You do not need to step sequentially through each intermediate Hardened Release (e.g., Base → HR1 → HR2).

Hope this helps clarify! Let us know if you have any further questions.