CVE-2026-63020: F5 BIG-IP Access Policy Manager
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
- F5 BIG-IP Access Policy Manager: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Advanced Firewall Manager: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Advanced Web Application Firewall: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Analytics: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Application Acceleration Manager: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Application Security Manager: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Application Visibility And Reporting: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Automation Toolchain: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Carrier-Grade Nat: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Container Ingress Services: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Ddos Hybrid Defender: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Domain Name System: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Edge Gateway: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Fraud Protection Service: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Global Traffic Manager: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Link Controller: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Local Traffic Manager: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Policy Enforcement Manager: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP SSL Orchestrator: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Webaccelerator: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
- F5 BIG-IP Websafe: from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 21.0.0, up to and including 21.1.0
Published 2026-09-02. Last modified 2026-09-15.