ctipilot.ch

SPIP before 4.4.21 — second unconditional pre-auth RCE, affecting 4.4.20 itself; exploited in the wild August 2026; identifier added to CERT-FR's advisory 2026-08-24

cve · CVE-2026-77806 single-source-national-cert

Coverage timeline
1
first 2026-08-24 → last 2026-08-24
Peak priority
notable
1 notable
Sources cited
2
1 hosts
Sections touched
1
updates
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
SPIP

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-24/spip-second-flaw-cve-2026-77806-assigned-certfr-advisories · ATT&CK page ↗

Story timeline

  1. 2026-08-24UPDATE — SPIP's second pre-auth RCE now has an identifier: CVE-2026-77806, added to CERT-FR's advisory on 2026-08-24, closing the gap that made it invisible to CVE-keyed patching
    updatesThe SPIP flaw that had no CVE to track now has one — re-run the vulnerability-management match

Where this entity is cited

  • updates1

Source distribution

  • cert.ssi.gouv.fr2 (100%)

explore in graph

Entries about SPIP before 4.4.21 — second unconditional pre-auth RCE, affecting 4.4.20 itself; exploited in the wild August 2026; identifier added to CERT-FR's advisory 2026-08-24 (1)

2026-08-24 · view entry permalink →

NOTABLECVE-2026-77806exploitedupdateNATOA2

UPDATE — SPIP's second pre-auth RCE now has an identifier: CVE-2026-77806, added to CERT-FR's advisory on 2026-08-24, closing the gap that made it invisible to CVE-keyed patching

UPDATE · originally covered SPIP shipped two emergency releases in three days, each fixing an unconditional pre-authentication RCE the vendor says is already being exploited — and only the first one has a CVE (2026-08-22)

the original entry's closing warning was that the second flaw "has no CVE identifier at all — so a vulnerability-management process driven by CVE feeds cannot see the newer of the two." That gap closed on 2026-08-24, and closing it is itself the operational delta.

CERT-FR updated its advisory for the 4.4.21 flaw on 2026-08-24 to add the identifier now assigned to it, CVE-2026-77806, and updated its companion advisory for the 4.4.20 flaw the same day to add CVE-2026-77647 (CERT-FR, 2026-08-24; CERT-FR, 2026-08-24). CERT-FR carries one advisory per flaw — the split the original entry described in prose is now the split of the identifier records too, and the exploitation statement stands as before, attributed by CERT-FR to the vendor.

L'éditeur indique que cette vulnérabilité est activement exploitée.

CERT-FR / ANSSI 2026-08-24
vulnerability24 Aug 09:55Zsingle-source · national CERTOpen finding ↗