CVE-2026-20730
Severity CVSS v4.0:
LOW
Type:
CWE-200
Information Leak / Disclosure
Publication date:
04/02/2026
Last modified:
13/02/2026
Description
A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Impact
Base Score 4.0
2.00
Severity 4.0
LOW
Base Score 3.x
3.30
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | 16.1.0 (including) | 16.1.6 (including) |
| cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | 17.1.0 (including) | 17.1.3.1 (excluding) |
| cpe:2.3:a:f5:big-ip_access_policy_manager:17.5.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:big-ip_access_policy_manager:17.5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:big-ip_access_policy_manager_client:*:*:*:*:*:*:*:* | 7.2.5 (including) | 7.2.6.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



