# CVE-2026-63020

## Summary

- **CVE ID:** CVE-2026-63020
- **Severity:** LOW
- **CVSS Score:** 3.1 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-451
- **Published:** Sep 2, 2026
- **Last Modified:** Sep 2, 2026

## Description

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages 





Impact:


An attacker may trick authenticated BIG-IP users 
into accessing malicious links and reflect a spoofed error message in 
the victim's BIG-IP Configuration utility web browser session. This is a
 control plane issue; there is no data plane exposure.





Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

## Affected Products

- F5 — BIG-IP (21.1.0)
- F5 — BIG-IP (21.0.0)
- F5 — BIG-IP (17.5.0)
- F5 — BIG-IP (17.1.0)

## References

- [CNA](https://my.f5.com/manage/s/article/K000161728)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 8.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._