THE page discusses a critical security vulnerability identified as CVE-2026-77806, which affects the SPIP content management system (CMS). This unauthenticated remote code execution (RCE) vulnerability has a CVSS score of 9.8, indicating its severity. It impacts all versions prior to 4.4.21, allowing unauthorized attackers to execute arbitrary code without login. The vulnerability has been actively exploited in the wild, with public exploit code available. The official patch is included in version 4.4.21, which should be implemented immediately to mitigate risks.
Critical SPIP flaw CVE-2026-77806 lets hackers run code remotely
CyberSIXT Evidence Panel
Article by CyberSIXT