CVE-2026-83627: Unauthenticated Remote Code Execution Vulnerability Disclosed

CVE-2026-83627: Unauthenticated Remote Code Execution Vulnerability Disclosed

First seen 5 Sep 2026, 16:14 UTC db.gcve.euvulnerability.circl.lu 72.0

Article Content

Browse articles
ThreatCluster

A critical vulnerability, CVE-2026-83627, has been identified in Hummingbird versions up to 3.21.0, allowing unauthenticated remote code execution via the cookie name in the page cache debug log. This vulnerability was reported to be actively exploited, with a public proof of concept available. Users of Hummingbird are urged to patch their systems immediately, as the vulnerability has been confirmed as successfully patched by the reporting user. The vulnerability affects a wide range of users relying on Hummingbird for speed optimization, caching, and CDN functionalities. Detection rules for this vulnerability are available from Rulezet. The vulnerability was published on September 5, 2026.

Key Points: • CVE-2026-83627 allows unauthenticated remote code execution in Hummingbird <=3.21.0. • Public proof of concept and active exploitation have been confirmed. • Users are advised to apply patches immediately to mitigate risks.

Ask AI about this cluster

Timeline

2026-09-05
CVE-2026-83627 published
A critical vulnerability in Hummingbird was disclosed, allowing unauthenticated remote code execution.
vulnerability.circl.lu
2026-09-05
Public proof of concept released
A proof of concept for exploiting CVE-2026-83627 was made publicly available, increasing risks for users.
db.gcve.eu
2026-09-05
Vulnerability confirmed as patched
The vulnerability was reported as successfully patched by the user who discovered it.
vulnerability.circl.lu