ctipilot.ch
← Back to the live brief
NOTABLECVE-2026-77806exploitedupdateNATOA2vulnerability

UPDATE — SPIP's second pre-auth RCE now has an identifier: CVE-2026-77806, added to CERT-FR's advisory on 2026-08-24, closing the gap that made it invisible to CVE-keyed patching

discovered 2026-08-24 09:55 UTCrun 2026-08-24T0902Z-audit2 sourcessingle-source · national CERT

UPDATE · originally covered SPIP shipped two emergency releases in three days, each fixing an unconditional pre-authentication RCE the vendor says is already being exploited — and only the first one has a CVE (2026-08-22)

the original entry's closing warning was that the second flaw "has no CVE identifier at all — so a vulnerability-management process driven by CVE feeds cannot see the newer of the two." That gap closed on 2026-08-24, and closing it is itself the operational delta.

CERT-FR updated its advisory for the 4.4.21 flaw on 2026-08-24 to add the identifier now assigned to it, CVE-2026-77806, and updated its companion advisory for the 4.4.20 flaw the same day to add CVE-2026-77647 (CERT-FR, 2026-08-24; CERT-FR, 2026-08-24). CERT-FR carries one advisory per flaw — the split the original entry described in prose is now the split of the identifier records too, and the exploitation statement stands as before, attributed by CERT-FR to the vendor.

L'éditeur indique que cette vulnérabilité est activement exploitée.

CERT-FR / ANSSI 2026-08-24

Defender actions

  • Re-run the vulnerability-management match on SPIP estates now that CVE-2026-77806 exists: any instance triaged between 2026-08-20 and 2026-08-24 off a CVE feed shows CVE-2026-77647 closed at 4.4.20 while the then-unnumbered second flaw left it exposed — confirm those instances are on 4.4.21, not 4.4.20.

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.