CVE-2026-63020: BIG-IP Configuration utility vulnerability
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages
Impact:
An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
The issue affects authenticated BIG-IP Configuration Utility users in the control plane. There is no data plane exposure.
What must an attacker do to exploit it?
An attacker must trick an authenticated BIG-IP user into accessing malicious links. Exploitation can result in spoofed error messages being reflected in that user's Configuration Utility browser session.
Are end-of-support BIG-IP software versions covered by the evaluation?
No. Software versions that have reached End of Technical Support (EoTS) are not evaluated.