vulnerability.circl.lu
CVE-2026-83627: Unauthenticated Remote Code Execution Vulnerability Disclosed
Article Content
A critical vulnerability, CVE-2026-83627, has been identified in Hummingbird versions up to 3.21.0, allowing unauthenticated remote code execution via the cookie name in the page cache debug log. This vulnerability was reported to be actively exploited, with a public proof of concept available. Users of Hummingbird are urged to patch their systems immediately, as the vulnerability has been confirmed as successfully patched by the reporting user. The vulnerability affects a wide range of users relying on Hummingbird for speed optimization, caching, and CDN functionalities. Detection rules for this vulnerability are available from Rulezet. The vulnerability was published on September 5, 2026.
Key Points: • CVE-2026-83627 allows unauthenticated remote code execution in Hummingbird <=3.21.0. • Public proof of concept and active exploitation have been confirmed. • Users are advised to apply patches immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.