Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
PoC publicBIG-IPOur summary
watchTowr Labs found that CVE-2026-94127 in F5 BIG-IP APM lets an unauthenticated attacker send an oversized Authorization header during an OAuth request, causing a heap overflow that can be developed into remote code execution. The issue affects BIG-IP APM 21.x and 17.x, and F5 reports active exploitation, making prompt installation of the available hotfixes important for exposed deployments.
Read at watchTowr Labs
watchTowr Labs publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.