CRITICAL 9.8 CVE-2026-77806 Published 21 Aug 2026

SPIP CMS Arbitrary Code Execution

Worried this affects one of your servers?

SPIP, a popular content management system, is affected by a critical security vulnerability.

SPIP before version 4.4.21 allows unauthenticated attackers to execute arbitrary code.

This is due to a code injection vulnerability in the analyse_resultat_skel function, which mishandles the X-Spip-Filtre HTTP request header.

Exploitation of this vulnerability has been observed in the wild since August 2026.

Reference: CVE-2026-77806 on NVD

← Back to Security News