Catalog / Cloudflare Developer Platform

WAF - WAF Release - 2026-10-06

5 days agosecurityaddedOriginal notes

This release introduces a new detection to mitigate a heap-based buffer overflow vulnerability in F5 BIG-IP, and enhances existing command injection protections by incorporating tested beta logic into the baseline rule.

Key Findings

  • CVE-2026-94127: A heap-based buffer overflow vulnerability in F5 BIG-IP. Attackers can exploit this flaw to execute arbitrary code on the affected system.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...a056caffN/ACommand Injection - Generic 8 - uri - BetaLogBlockThis rule is merged into the original rule "Command Injection - Generic 8 - uri" (ID: ...ee159e2e).
Cloudflare Managed Ruleset...7206c737N/AF5 BIG-IP - UnAuth Heap-Overflow - CVE:CVE-2026-94127LogBlockThis is a new detection.
Cloudflare Managed Ruleset...549f7356N/ANext.js - Cache Poisoning - CVE:CVE-2026-94543BlockBlockRule metadata description refined. Detection unchanged.