Spoofing attack in BIG-IP - CVE-2026-63020
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to spoof error messages in an authenticated BIG-IP user's Configuration utility web browser session.
The vulnerability exists due to user interface misrepresentation of critical information in an undisclosed BIG-IP Configuration utility page when authenticated BIG-IP users access malicious links. A remote attacker can trick authenticated BIG-IP users into accessing malicious links to spoof error messages in their Configuration utility web browser sessions.
This is a control plane issue with no data plane exposure.