CVE-2026-20730
F5 BIG-IP Virtual Edition (tier - best) vulnerability analysis and mitigation

Overview

CVE-2026-20730 is an information disclosure vulnerability (CWE-200) affecting F5 BIG-IP Edge Client and browser VPN clients on Windows. It allows a low-privileged local attacker to gain access to sensitive information without user interaction. Affected products include BIG-IP Access Policy Manager (APM) versions 16.1.0–16.1.6, 17.1.0–17.1.3.0, and 17.5.0–17.5.1, as well as BIG-IP Access Policy Manager Client versions 7.2.5 through 7.2.6.1. The vulnerability was published on February 4, 2026, with a patch made available on February 13, 2026. It carries a CVSS v3.1 base score of 3.3 (Low) and a CVSS v4.0 base score of 2.0 (Low) (F5 Advisory).

Technical details

The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), arising from improper protection of sensitive data within the BIG-IP Edge Client and browser VPN client processes on Windows. An attacker with low-level local privileges can read sensitive information — such as VPN credentials or connection configuration details — from the client application without requiring user interaction. Exploitation requires local access and the presence of specific conditions (CVSS attack requirements: Present), limiting the attack surface to authenticated local users on affected Windows systems. No public proof-of-concept or technical write-up detailing the precise exploitation mechanism has been published (F5 Advisory, Feedly).

Impact

Successful exploitation allows an authenticated local attacker with low privileges to read sensitive information from the BIG-IP Edge Client or browser VPN clients, potentially exposing VPN credentials, session tokens, or connection configuration details. The vulnerability has no impact on data integrity or system availability, and its scope is limited to the local system without lateral movement capability inherent to the flaw itself. However, exposed VPN credentials could be leveraged by an attacker for subsequent unauthorized network access (F5 Advisory).

Mitigation and workarounds

F5 has released patches addressing this vulnerability. Users should upgrade to the following fixed versions:

  • BIG-IP Access Policy Manager Client: 7.2.6.2 or later
  • BIG-IP Access Policy Manager 16.1.x: 16.1.7 or later
  • BIG-IP Access Policy Manager 17.1.x: 17.1.3.1 or later
  • BIG-IP Access Policy Manager 17.5.x: versions after 17.5.1

Software versions that have reached End of Technical Support (EoTS) are not evaluated. As interim mitigations, restrict local system access to authorized users only, apply the principle of least privilege to limit low-privilege account access to VPN client processes, and monitor for unauthorized access attempts on affected systems (F5 Advisory).

Community reactions

Coverage of CVE-2026-20730 was largely bundled with F5's broader February 2026 security update cycle, which addressed more critical vulnerabilities in BIG-IP and NGINX products. Security news outlets including CyberSecurityNews, GBHackers, and Heise covered the F5 patch release, though focus was primarily on higher-severity issues in the same advisory batch. No notable individual researcher commentary or significant community discussion specific to this low-severity CVE has been observed (CyberSecurityNews, GBHackers, Heise).

Additional resources


SourceThis report was generated using AI

Related F5 BIG-IP Virtual Edition (tier - best) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59762HIGH8.7
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesJul 15, 2026
CVE-2026-42920HIGH8.7
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42930HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42924HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_domain_name_system
NoYesMay 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management