CVE-2026-63020Low· 3.1▾ SunlitA vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages
Impact:
An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
big-ip_access_policy_manager >= 17.1.0, <= 17.1.3big-ip_access_policy_manager >= 17.5.0, <= 17.5.1big-ip_advanced_firewall_manager >= 17.1.0, <= 17.1.3big-ip_advanced_firewall_manager >= 17.5.0, <= 17.5.1big-ip_advanced_web_application_firewall >= 17.1.0, <= 17.1.3big-ip_advanced_web_application_firewall >= 17.5.0, <= 17.5.1big-ip_analytics >= 17.1.0, <= 17.1.3big-ip_analytics >= 17.5.0, <= 17.5.1big-ip_application_acceleration_manager >= 17.1.0, <= 17.1.3big-ip_application_acceleration_manager >= 17.5.0, <= 17.5.1big-ip_application_security_manager >= 17.1.0, <= 17.1.3big-ip_application_security_manager >= 17.5.0, <= 17.5.1big-ip_application_visibility_and_reporting >= 17.1.0, <= 17.1.3big-ip_application_visibility_and_reporting >= 17.5.0, <= 17.5.1big-ip_automation_toolchain >= 17.1.0, <= 17.1.3big-ip_automation_toolchain >= 17.5.0, <= 17.5.1big-ip_carrier-grade_nat >= 17.1.0, <= 17.1.3big-ip_carrier-grade_nat >= 17.5.0, <= 17.5.1big-ip_container_ingress_services >= 17.1.0, <= 17.1.3big-ip_container_ingress_services >= 17.5.0, <= 17.5.1big-ip_ddos_hybrid_defender >= 17.1.0, <= 17.1.3big-ip_ddos_hybrid_defender >= 17.5.0, <= 17.5.1big-ip_domain_name_system >= 17.1.0, <= 17.1.3big-ip_domain_name_system >= 17.5.0, <= 17.5.1big-ip_edge_gateway >= 17.1.0, <= 17.1.3big-ip_edge_gateway >= 17.5.0, <= 17.5.1big-ip_fraud_protection_service >= 17.1.0, <= 17.1.3big-ip_fraud_protection_service >= 17.5.0, <= 17.5.1big-ip_global_traffic_manager >= 17.1.0, <= 17.1.3big-ip_global_traffic_manager >= 17.5.0, <= 17.5.1big-ip_link_controller >= 17.1.0, <= 17.1.3big-ip_link_controller >= 17.5.0, <= 17.5.1big-ip_local_traffic_manager >= 17.1.0, <= 17.1.3big-ip_local_traffic_manager >= 17.5.0, <= 17.5.1big-ip_policy_enforcement_manager >= 17.1.0, <= 17.1.3big-ip_policy_enforcement_manager >= 17.5.0, <= 17.5.1big-ip_ssl_orchestrator >= 17.1.0, <= 17.1.3big-ip_ssl_orchestrator >= 17.5.0, <= 17.5.1big-ip_webaccelerator >= 17.1.0, <= 17.1.3big-ip_webaccelerator >= 17.5.0, <= 17.5.1big-ip_websafe >= 17.1.0, <= 17.1.3big-ip_websafe >= 17.5.0, <= 17.5.1big-ip_access_policy_manager >= 21.0.0, <= 21.1.0big-ip_advanced_firewall_manager >= 21.0.0, <= 21.1.0big-ip_advanced_web_application_firewall >= 21.0.0, <= 21.1.0big-ip_analytics >= 21.0.0, <= 21.1.0big-ip_application_acceleration_manager >= 21.0.0, <= 21.1.0big-ip_application_security_manager >= 21.0.0, <= 21.1.0big-ip_application_visibility_and_reporting >= 21.0.0, <= 21.1.0big-ip_automation_toolchain >= 21.0.0, <= 21.1.0big-ip_carrier-grade_nat >= 21.0.0, <= 21.1.0big-ip_container_ingress_services >= 21.0.0, <= 21.1.0big-ip_ddos_hybrid_defender >= 21.0.0, <= 21.1.0big-ip_domain_name_system >= 21.0.0, <= 21.1.0big-ip_edge_gateway >= 21.0.0, <= 21.1.0big-ip_fraud_protection_service >= 21.0.0, <= 21.1.0big-ip_global_traffic_manager >= 21.0.0, <= 21.1.0big-ip_link_controller >= 21.0.0, <= 21.1.0big-ip_local_traffic_manager >= 21.0.0, <= 21.1.0big-ip_policy_enforcement_manager >= 21.0.0, <= 21.1.0big-ip_ssl_orchestrator >= 21.0.0, <= 21.1.0big-ip_webaccelerator >= 21.0.0, <= 21.1.0big-ip_websafe >= 21.0.0, <= 21.1.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-94127Critical· 9.8When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)
CVE-2026-40698High· 8.7A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resu…
CVE-2026-90439Medium· 6.5NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module
CVE-2026-42945High· 8.1NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module
CVE-2026-8711High· 8.1NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGIN…
CVE-2026-32682Medium· 6.5When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPC…