securityonline.info 8/21/2026, 5:10:02 PM · external

Critical SPIP flaw CVE-2026-77806 lets hackers run code remotely

Critical SPIP flaw CVE-2026-77806 lets hackers run code remotely
CyberSIXT Evidence Panel
Primary Source blog.spip.net
CISA KEV Not in KEV
Patch Patch Status Unknown

THE page discusses a critical security vulnerability identified as CVE-2026-77806, which affects the SPIP content management system (CMS). This unauthenticated remote code execution (RCE) vulnerability has a CVSS score of 9.8, indicating its severity. It impacts all versions prior to 4.4.21, allowing unauthorized attackers to execute arbitrary code without login. The vulnerability has been actively exploited in the wild, with public exploit code available. The official patch is included in version 4.4.21, which should be implemented immediately to mitigate risks.

View Primary Source Via securityonline.info

Article by CyberSIXT