2026-08-24 · view entry permalink →
UPDATE — SPIP's second pre-auth RCE now has an identifier: CVE-2026-77806, added to CERT-FR's advisory on 2026-08-24, closing the gap that made it invisible to CVE-keyed patching
UPDATE · originally covered SPIP shipped two emergency releases in three days, each fixing an unconditional pre-authentication RCE the vendor says is already being exploited — and only the first one has a CVE (2026-08-22)
the original entry's closing warning was that the second flaw "has no CVE identifier at all — so a vulnerability-management process driven by CVE feeds cannot see the newer of the two." That gap closed on 2026-08-24, and closing it is itself the operational delta.
CERT-FR updated its advisory for the 4.4.21 flaw on 2026-08-24 to add the identifier now assigned to it, CVE-2026-77806, and updated its companion advisory for the 4.4.20 flaw the same day to add CVE-2026-77647 (CERT-FR, 2026-08-24; CERT-FR, 2026-08-24). CERT-FR carries one advisory per flaw — the split the original entry described in prose is now the split of the identifier records too, and the exploitation statement stands as before, attributed by CERT-FR to the vendor.
L'éditeur indique que cette vulnérabilité est activement exploitée.