CVE Tools

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

watchTowr LabsBy Sina Kheirkhah (@SinSinology)

PoC publicBIG-IP

Our summary

watchTowr Labs found that CVE-2026-94127 in F5 BIG-IP APM lets an unauthenticated attacker send an oversized Authorization header during an OAuth request, causing a heap overflow that can be developed into remote code execution. The issue affects BIG-IP APM 21.x and 17.x, and F5 reports active exploitation, making prompt installation of the available hotfixes important for exposed deployments.

Read at watchTowr Labs

watchTowr Labs publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store