THE content discusses a critical vulnerability (CVE-2026-77647) within the SPIP content management system, rated CVSS 9.8, indicating a serious risk of unauthenticated remote code execution (RCE). The flaw affects all versions prior to 4.4.20, allowing attackers to execute arbitrary code without login. Exploits have been observed in the wild, necessitating urgent updates to version 4.4.20, which includes this fix alongside other bug fixes. The vulnerability's root cause arises from improper handling of PHP code blocks, making it imperative for users to patch their systems.
CVE-2026-77647 (CVSS 9.8): Unauthenticated SPIP RCE Exploited in the Wild
CyberSIXT Evidence Panel
Article by CyberSIXT