securityonline.info 8/21/2026, 3:50:40 AM · external

CVE-2026-77647 (CVSS 9.8): Unauthenticated SPIP RCE Exploited in the Wild

CVE-2026-77647 (CVSS 9.8): Unauthenticated SPIP RCE Exploited in the Wild
CyberSIXT Evidence Panel
Primary Source blog.spip.net
CISA KEV Not in KEV
Patch Patch Status Unknown

THE content discusses a critical vulnerability (CVE-2026-77647) within the SPIP content management system, rated CVSS 9.8, indicating a serious risk of unauthenticated remote code execution (RCE). The flaw affects all versions prior to 4.4.20, allowing attackers to execute arbitrary code without login. Exploits have been observed in the wild, necessitating urgent updates to version 4.4.20, which includes this fix alongside other bug fixes. The vulnerability's root cause arises from improper handling of PHP code blocks, making it imperative for users to patch their systems.

View Primary Source Via securityonline.info

Article by CyberSIXT