
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-63020 is a spoofing vulnerability in an undisclosed F5 BIG-IP Configuration utility page that allows an unauthenticated attacker to reflect spoofed error messages in an authenticated user's browser session. Disclosed on September 2, 2026, it affects BIG-IP versions 17.1.0 through 17.1.3.4, 17.5.0 through 17.5.1.8, 21.0.0 through 21.0.0.3, and 21.1.0 through 21.1.0.1. This is a control plane issue only — there is no data plane exposure. It carries a CVSS v3.1 base score of 3.1 (Low) and a CVSS v4.0 base score of 2.3 (Low) (GitHub Advisory, F5 Advisory).
The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), where the BIG-IP Configuration utility fails to properly validate or sanitize content reflected in error messages on an undisclosed page. An attacker crafts a malicious link that, when clicked by an authenticated BIG-IP user, causes a spoofed error message to be reflected within the victim's active Configuration utility web browser session — a form of reflected content injection. Exploitation requires high attack complexity and passive user interaction (the victim must follow a crafted link), and no privileges are required on the attacker's part (GitHub Advisory, F5 Advisory).
Successful exploitation allows an attacker to display spoofed error messages within an authenticated BIG-IP administrator's Configuration utility session, potentially deceiving the user into taking unintended actions or disclosing credentials through social engineering. The impact is limited to low integrity loss on the vulnerable system; there is no confidentiality or availability impact, and no data plane exposure. Lateral movement or direct system compromise is not achievable through this vulnerability alone (GitHub Advisory, F5 Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.186% (8th percentile), indicating a low probability of exploitation in the near term. The NVD SSVC assessment also classifies exploitation as "none" and the vulnerability as non-automatable (GitHub Advisory).
F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1. Organizations should upgrade to these versions as the primary remediation. As interim mitigations, restrict access to the BIG-IP Configuration utility to trusted networks and authorized users only, and educate administrators to verify the legitimacy of links before clicking, particularly those directing to the Configuration utility. Software versions that have reached End of Technical Support (EoTS) are not evaluated and should be upgraded (F5 Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."