CRITICAL
9.8 CVE-2026-77806 Published 21 Aug 2026
SPIP CMS Arbitrary Code Execution
Worried this affects one of your servers?
SPIP, a popular content management system, is affected by a critical security vulnerability.
SPIP before version 4.4.21 allows unauthenticated attackers to execute arbitrary code.
This is due to a code injection vulnerability in the analyse_resultat_skel function, which mishandles the X-Spip-Filtre HTTP request header.
Exploitation of this vulnerability has been observed in the wild since August 2026.
Reference: CVE-2026-77806 on NVD
← Back to Security News