WAF – WAF Release – 2026-10-06

This release introduces a new detection to mitigate a heap-based buffer overflow vulnerability in F5 BIG-IP, and enhances existing command injection protections by incorporating tested beta logic into the baseline rule.

Key Findings

  • CVE-2026-94127: A heap-based buffer overflow vulnerability in F5 BIG-IP. Attackers can exploit this flaw to execute arbitrary code on the affected system.
Ruleset Rule ID Legacy Rule ID Description Previous Action New Action Comments
Cloudflare Managed Ruleset N/A Command Injection – Generic 8 – uri – Beta Log Block This rule is merged into the original rule "Command Injection – Generic 8 – uri" (ID: ).
Cloudflare Managed Ruleset N/A F5 BIG-IP – UnAuth Heap-Overflow – CVE:CVE-2026-94127 Log Block This is a new detection.
Cloudflare Managed Ruleset N/A Next.js – Cache Poisoning – CVE:CVE-2026-94543 Block Block Rule metadata description refined. Detection unchanged.

Source: Cloudflare

Share This Update