PT-2026-84759 · F5 · Big-Ip

CVE-2026-63020

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages 
Impact:
An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Fix

UI Misrepresentation of Critical Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63020

Affected Products

Big-Ip