CTIPilot

SPIP

product · product:spip

Coverage timeline
1
first 2026-08-22 → last 2026-08-22
Peak priority
high
1 high
Sources cited
5
3 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-22/spip-two-unconditional-preauth-rce-releases-three-days-apart · ATT&CK page ↗

Story timeline

  1. 2026-08-22SPIP shipped two emergency releases in three days, each fixing an unconditional pre-authentication RCE the vendor says is already being exploited, and only the first one has a CVE
    trending-vulnerabilities4.4.20 fixed a flaw in every version; 4.4.21 fixed a second one in 4.4.20 itself, with no identifier to track it by

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • blog.spip.net2 (40%)
  • cert.ssi.gouv.fr2 (40%)
  • euvd.enisa.europa.eu1 (20%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about SPIP (1)

2026-08-22 · view entry permalink →

HIGHCVE-2026-77647 +1exploitedupdatedNATOA2

SPIP shipped two emergency releases in three days, each fixing an unconditional pre-authentication RCE the vendor says is already being exploited, and only the first one has a CVE

SPIP's maintainers published a critical security release on Monday 17 August 2026 and another on Thursday 20 August. The release notes describe their respective flaws in near-identical language, and the wording is unusually unhedged for a vendor bulletin: 4.4.20 fixes an unconditional, no-prerequisites pre-authentication remote code execution vulnerability affecting all versions of SPIP (SPIP, 2026-08-17), and 4.4.21 fixes an unconditional, no-prerequisites pre-authentication remote code execution vulnerability affecting version 4.4.20; the release that had just shipped three days earlier (SPIP, 2026-08-20). Both notes then carry the same follow-on sentence word for word: the flaw is not handled by the security screen, it is imperative to update the site very quickly, and exploitation attempts have already been observed in the wild. The security screen (SPIP's own request-filtering layer, which many administrators treat as a standing compensating control against exactly this bug class) is therefore ruled out by the vendor as a mitigation for both. Both were reported anonymously through France's national cybersecurity agency, and the earlier one credits a researcher by handle for help with the analysis and the fix (SPIP, 2026-08-17).

Only the first of the two has an identifier. CVE-2026-77647 is the 4.4.20 fix: the EU vulnerability database record cites that release note directly, bounds the affected range as everything below 4.4.20, scores it CVSS 3.1 9.8 with an EPSS of 0.82, and states in its own description that the flaw is exploited in the wild in August 2026 (ENISA EU Vulnerability Database, 2026-08-20). Its published root cause is incorrect identification of PHP open tags combined with a value-exporting function's mishandling of certain cases such as the presence of a < character (ENISA EU Vulnerability Database, 2026-08-20). The 4.4.21 flaw has no CVE, no CWE and no published root cause; CERT-FR relayed it as an advisory the following day, recording remote code execution as the risk, giving the affected range as all versions before 4.4.21, and attributing the active-exploitation statement to the vendor rather than asserting it itself (CERT-FR, 2026-08-21). Whether it is a bypass of the fix that shipped three days earlier or an independent flaw of the same shape is not something any source says, and this entry does not guess.

Triage: a public CMS receives constant automated probing, so request volume and 404 noise separate nothing. The discriminator is what happens after a request rather than the request itself, a web-server worker process spawning a shell or interpreter child, or a file appearing under the document root whose modification time matches no deployment, upgrade or editorial action. On a platform this widely deployed across French-language public administration, and with the earlier flaw's CVE record already recording in-the-wild exploitation, the base rate for that sequence being benign is low.

Cette version corrige une vulnérabilité universelle (sans conditions) pré-authentification RCE qui touche toutes les versions de SPIP.

SPIP (4.4.20 release note)

Cette version corrige une vulnérabilité universelle (sans conditions) pré-authentification RCE qui touche la version 4.4.20 de SPIP.

SPIP (4.4.21 release note)

Systèmes affectés SPIP versions antérieures à 4.4.21

L'éditeur indique que cette vulnérabilité est activement exploitée.

CERT-FR / ANSSI 2026-08-21

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026.

ENISA EU Vulnerability Database 2026-08-20
Updaterun 2026-08-24T0902Z-auditactionscvesregionssectorssourcesbody

The original entry's closing warning was that the second flaw "has no CVE identifier at all, so a vulnerability-management process driven by CVE feeds cannot see the newer of the two." That gap closed on 2026-08-24, and closing it is itself the operational delta.

CERT-FR updated its advisory for the 4.4.21 flaw on 2026-08-24 to add the identifier now assigned to it, CVE-2026-77806, and updated its companion advisory for the 4.4.20 flaw the same day to add CVE-2026-77647 (CERT-FR, 2026-08-24; CERT-FR, 2026-08-24). CERT-FR carries one advisory per flaw; the split the original entry described in prose is now the split of the identifier records too, and the exploitation statement stands as before, attributed by CERT-FR to the vendor.

vulnerability22 Aug 05:07Zmulti-sourceOpen finding ↗