CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

SPIP before 4.4.20, unconditional pre-authentication RCE reported anonymously via ANSSI; the vendor's bulletin states exploitation attempts were already observed in the wild (August 2026). A second, distinct unconditional pre-auth RCE affects 4.4.20 itself and is fixed only in 4.4.21, that one is CVE-2026-77806. No mechanism is described by any citable vendor or CERT source.

cve · CVE-2026-77647

Coverage
1
first 2026-08-22 → last 2026-08-24
Latest activity
2026-08-24
4.4.20 fixed a flaw in every version; 4.4.21 fixed a second one in 4.4.20 itself, with no identifier to track…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, education · regions: europe, switzerland
Sources cited
5
3 hosts

Action items (3)

Do-now tasks recorded on the entries about CVE-2026-77647, newest first. Check the date before acting on an older one.

  • Upgrade every SPIP site to 4.4.21 (not to 4.4.20, which the vendor states is itself affected by the second flaw) and do it as an out-of-band change: the vendor states exploitation attempts on both flaws have already been observed. Do not rely on SPIP's built-in security screen as an interim control; the vendor states in both release notes that it does not cover these flaws.
    2026-08-22CVE-2026-77647 +1
  • Add SPIP to the manual watch list of any vulnerability-management process that triggers only on CVE identifiers: the 4.4.21 flaw has none, so a CVE-driven pipeline will report the estate clean once CVE-2026-77647 is closed while the newer flaw is still open.
    2026-08-22CVE-2026-77647 +1
  • Re-run the vulnerability-management match on SPIP estates now that CVE-2026-77806 exists: any instance triaged between 2026-08-20 and 2026-08-24 off a CVE feed shows CVE-2026-77647 closed at 4.4.20 while the then-unnumbered second flaw left it exposed; confirm those instances are on 4.4.21, not 4.4.20.
    2026-08-22CVE-2026-77647 +1

Defender insights

What each entry about CVE-2026-77647 tells a defender to do, newest first.

2026-08-22HIGHexploited4.4.20 fixed a flaw in every version; 4.4.21 fixed a second one in 4.4.20 itself, with no identifier to track it by

Latest update · triage

Story timeline

  1. 2026-08-22SPIP shipped two emergency releases in three days, each fixing an unconditional pre-authentication RCE the vendor says is already being exploited, and only the first one has a CVE
    trending-vulnerabilities4.4.20 fixed a flaw in every version; 4.4.21 fixed a second one in 4.4.20 itself, with no identifier to track it by
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-22/spip-two-unconditional-preauth-rce-releases-three-days-apart · ATT&CK page ↗

Entries about SPIP before 4.4.20, unconditional pre-authentication RCE reported anonymously via ANSSI; the vendor's bulletin states exploitation attempts were already observed in the wild (August 2026). A second, distinct unconditional pre-auth RCE affects 4.4.20 itself and is fixed only in 4.4.21, that one is CVE-2026-77806. No mechanism is described by any citable vendor or CERT source. (1)

2026-08-22 · view entry permalink →

HIGHCVE-2026-77647 +1exploitedupdatedNATOA2

SPIP shipped two emergency releases in three days, each fixing an unconditional pre-authentication RCE the vendor says is already being exploited, and only the first one has a CVE

SPIP's maintainers published a critical security release on Monday 17 August 2026 and another on Thursday 20 August. The release notes describe their respective flaws in near-identical language, and the wording is unusually unhedged for a vendor bulletin: 4.4.20 fixes an unconditional, no-prerequisites pre-authentication remote code execution vulnerability affecting all versions of SPIP (SPIP, 2026-08-17), and 4.4.21 fixes an unconditional, no-prerequisites pre-authentication remote code execution vulnerability affecting version 4.4.20; the release that had just shipped three days earlier (SPIP, 2026-08-20). Both notes then carry the same follow-on sentence word for word: the flaw is not handled by the security screen, it is imperative to update the site very quickly, and exploitation attempts have already been observed in the wild. The security screen (SPIP's own request-filtering layer, which many administrators treat as a standing compensating control against exactly this bug class) is therefore ruled out by the vendor as a mitigation for both. Both were reported anonymously through France's national cybersecurity agency, and the earlier one credits a researcher by handle for help with the analysis and the fix (SPIP, 2026-08-17).

Only the first of the two has an identifier. CVE-2026-77647 is the 4.4.20 fix: the EU vulnerability database record cites that release note directly, bounds the affected range as everything below 4.4.20, scores it CVSS 3.1 9.8 with an EPSS of 0.82, and states in its own description that the flaw is exploited in the wild in August 2026 (ENISA EU Vulnerability Database, 2026-08-20). Its published root cause is incorrect identification of PHP open tags combined with a value-exporting function's mishandling of certain cases such as the presence of a < character (ENISA EU Vulnerability Database, 2026-08-20). The 4.4.21 flaw has no CVE, no CWE and no published root cause; CERT-FR relayed it as an advisory the following day, recording remote code execution as the risk, giving the affected range as all versions before 4.4.21, and attributing the active-exploitation statement to the vendor rather than asserting it itself (CERT-FR, 2026-08-21). Whether it is a bypass of the fix that shipped three days earlier or an independent flaw of the same shape is not something any source says, and this entry does not guess.

Triage: a public CMS receives constant automated probing, so request volume and 404 noise separate nothing. The discriminator is what happens after a request rather than the request itself, a web-server worker process spawning a shell or interpreter child, or a file appearing under the document root whose modification time matches no deployment, upgrade or editorial action. On a platform this widely deployed across French-language public administration, and with the earlier flaw's CVE record already recording in-the-wild exploitation, the base rate for that sequence being benign is low.

Cette version corrige une vulnérabilité universelle (sans conditions) pré-authentification RCE qui touche toutes les versions de SPIP.

SPIP (4.4.20 release note)

Cette version corrige une vulnérabilité universelle (sans conditions) pré-authentification RCE qui touche la version 4.4.20 de SPIP.

SPIP (4.4.21 release note)

Systèmes affectés SPIP versions antérieures à 4.4.21

L'éditeur indique que cette vulnérabilité est activement exploitée.

CERT-FR / ANSSI 2026-08-21

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026.

ENISA EU Vulnerability Database 2026-08-20
Updaterun 2026-08-24T0902Z-auditactionscvesregionssectorssourcesbody

The original entry's closing warning was that the second flaw "has no CVE identifier at all, so a vulnerability-management process driven by CVE feeds cannot see the newer of the two." That gap closed on 2026-08-24, and closing it is itself the operational delta.

CERT-FR updated its advisory for the 4.4.21 flaw on 2026-08-24 to add the identifier now assigned to it, CVE-2026-77806, and updated its companion advisory for the 4.4.20 flaw the same day to add CVE-2026-77647 (CERT-FR, 2026-08-24; CERT-FR, 2026-08-24). CERT-FR carries one advisory per flaw; the split the original entry described in prose is now the split of the identifier records too, and the exploitation statement stands as before, attributed by CERT-FR to the vendor.

vulnerability22 Aug 05:07Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • blog.spip.net2 (40%)
  • cert.ssi.gouv.fr2 (40%)
  • euvd.enisa.europa.eu1 (20%)