WAF Release - 2026-10-06
This release introduces a new detection to mitigate a heap-based buffer overflow vulnerability in F5 BIG-IP, and enhances existing command injection protections by incorporating tested beta logic into the baseline rule.
Key Findings
- CVE-2026-94127: A heap-based buffer overflow vulnerability in F5 BIG-IP. Attackers can exploit this flaw to execute arbitrary code on the affected system.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | N/A | Command Injection - Generic 8 - uri - Beta | Log | Block | This rule is merged into the original rule "Command Injection - Generic 8 - uri" (ID: ). | |
| Cloudflare Managed Ruleset | N/A | F5 BIG-IP - UnAuth Heap-Overflow - CVE:CVE-2026-94127 | Log | Block | This is a new detection. | |
| Cloudflare Managed Ruleset | N/A | Next.js - Cache Poisoning - CVE:CVE-2026-94543 | Block | Block | Rule metadata description refined. Detection unchanged. |