watchTowr Exposes F5 BIG-IP Auth-Header Heap Overflow RCE, Rips LLM-Driven Vuln Flood

dyn___ · x · 2026-09-24

watchTowr Labs discloses CVE-2026-94127, an unauthenticated heap-overflow-to-RCE in F5 BIG-IP rooted in its authentication header handling — mocked as "1998 called and wants its vuln back." The writeup also argues that with everyone now using LLMs to find and reproduce vulnerabilities, disclosure has become a free-for-all: many "proofs of exploitation" on social media are LLM-generated slop payloads, and their appearance in accesslog is not evidence of real exploitation.

Original post →

More from Safety

Safety channel →