watchTowr Discloses F5 BIG-IP Auth Header Heap Overflow RCE

watchTowr Labs disclosed an unauthenticated heap overflow RCE in F5 BIG-IP, CVE-2026-94127, rooted in authentication header handling. The firm mocked it as a 20-year-old primitive returning as a '1998 bug' and criticized the flood of LLM-driven vulnerability hunting.

2026-09-24 ~ 2026-09-24 · 2 related posts