Skip to content

Changelog

New updates and improvements at Cloudflare.

Back to all posts

WAF Release - 2026-10-06

View as MarkdownAgent setup

This release introduces a new detection to mitigate a heap-based buffer overflow vulnerability in F5 BIG-IP, and enhances existing command injection protections by incorporating tested beta logic into the baseline rule.

Key Findings

  • CVE-2026-94127: A heap-based buffer overflow vulnerability in F5 BIG-IP. Attackers can exploit this flaw to execute arbitrary code on the affected system.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ACommand Injection - Generic 8 - uri - BetaLogBlockThis rule is merged into the original rule "Command Injection - Generic 8 - uri" (ID: ).
Cloudflare Managed RulesetN/AF5 BIG-IP - UnAuth Heap-Overflow - CVE:CVE-2026-94127LogBlockThis is a new detection.
Cloudflare Managed RulesetN/ANext.js - Cache Poisoning - CVE:CVE-2026-94543BlockBlockRule metadata description refined. Detection unchanged.