BIG-IP Config Utility Message Spoofing Vulnerability (CVE-2026-63020)
CVE-2026-63020 Published on September 2, 2026
BIG-IP Configuration utility vulnerability
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages
Impact:
An attacker may trick authenticated BIG-IP users
into accessing malicious links and reflect a spoofed error message in
the victim's BIG-IP Configuration utility web browser session. This is a
control plane issue; there is no data plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Vulnerability Analysis
CVE-2026-63020 is exploitable with network access, requires user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and no impact on availability.
Weakness Type
User Interface (UI) Misrepresentation of Critical Information
The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
Products Associated with CVE-2026-63020
Want to know whenever a new CVE is published for F5 Networks Big Ip? stack.watch will email you.
Affected Versions
F5 BIG-IP:- Version 21.1.0 and below 21.1.0.1 is affected.
- Version 21.0.0 and below 21.0.0.3 is affected.
- Version 17.5.0 and below 17.5.1.8 is affected.
- Version 17.1.0 and below 17.1.3.4 is affected.