Spoofing Vulnerability in BIG-IP Configuration Utility by F5
CVE-2026-63020

2.3LOW

Key Information:

Vendor

F5

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-63020?

A security flaw exists in a specific page of the BIG-IP Configuration utility from F5. This vulnerability allows attackers to deceive authenticated users by redirecting them to malicious links, which results in the display of spoofed error messages within their web browser session. The issue lies within the control plane, ensuring that there is no exposure to the data plane.

Affected Version(s)

BIG-IP 21.1.0 < 21.1.0.1

BIG-IP 21.0.0 < 21.0.0.3

BIG-IP 17.5.0 < 17.5.1.8

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5 acknowledges Michał Majchrowicz, Marcin Wyczechowski and Piotr Zdunek (members of the AFINE Team) for bringing this issue to our attention and following the highest standards of coordinated disclosure.
.