2026-08-22HIGHexploited4.4.20 fixed a flaw in every version; 4.4.21 fixed a second one in 4.4.20 itself, with no identifier to track it by
SPIP before 4.4.20, unconditional pre-authentication RCE reported anonymously via ANSSI; the vendor's bulletin states exploitation attempts were already observed in the wild (August 2026). A second, distinct unconditional pre-auth RCE affects 4.4.20 itself and is fixed only in 4.4.21, that one is CVE-2026-77806. No mechanism is described by any citable vendor or CERT source.
cve · CVE-2026-77647
Coverage
1
first 2026-08-22 → last 2026-08-24
Latest activity
2026-08-24
4.4.20 fixed a flaw in every version; 4.4.21 fixed a second one in 4.4.20 itself, with no identifier to track…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, education · regions: europe, switzerland
Sources cited
5
3 hosts
Action items (3)
Do-now tasks recorded on the entries about CVE-2026-77647, newest first. Check the date before acting on an older one.
- Upgrade every SPIP site to 4.4.21 (not to 4.4.20, which the vendor states is itself affected by the second flaw) and do it as an out-of-band change: the vendor states exploitation attempts on both flaws have already been observed. Do not rely on SPIP's built-in security screen as an interim control; the vendor states in both release notes that it does not cover these flaws.2026-08-22CVE-2026-77647 +1
- Add SPIP to the manual watch list of any vulnerability-management process that triggers only on CVE identifiers: the 4.4.21 flaw has none, so a CVE-driven pipeline will report the estate clean once CVE-2026-77647 is closed while the newer flaw is still open.2026-08-22CVE-2026-77647 +1
- Re-run the vulnerability-management match on SPIP estates now that CVE-2026-77806 exists: any instance triaged between 2026-08-20 and 2026-08-24 off a CVE feed shows CVE-2026-77647 closed at 4.4.20 while the then-unnumbered second flaw left it exposed; confirm those instances are on 4.4.21, not 4.4.20.2026-08-22CVE-2026-77647 +1
Defender insights
What each entry about CVE-2026-77647 tells a defender to do, newest first.
Latest update · triage
Story timeline
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-22/spip-two-unconditional-preauth-rce-releases-three-days-apart · ATT&CK page ↗
Entries about SPIP before 4.4.20, unconditional pre-authentication RCE reported anonymously via ANSSI; the vendor's bulletin states exploitation attempts were already observed in the wild (August 2026). A second, distinct unconditional pre-auth RCE affects 4.4.20 itself and is fixed only in 4.4.21, that one is CVE-2026-77806. No mechanism is described by any citable vendor or CERT source. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- SPIP×1
- SPIP before 4.4.21, second unconditional pre-auth RCE, affecting 4.4.20 itself; exploited in the wild August 2026; identifier added to CERT-FR's advisory 2026-08-24×1
Where this entity is cited
Source distribution
- blog.spip.net2 (40%)
- cert.ssi.gouv.fr2 (40%)
- euvd.enisa.europa.eu1 (20%)
External references
All cited sources (5)
- blog.spip.netprimarySPIPhttps://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-20.html
- blog.spip.netprimarySPIPhttps://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.html
- cert.ssi.gouv.frCERT-FR / ANSSIhttps://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1033/
- cert.ssi.gouv.frCERT-FR / ANSSIhttps://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1063/
- euvd.enisa.europa.euENISA EU Vulnerability Databasehttps://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-63757