CVE-2026-77647Active Exploitation

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 8 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days

What's happening

  • Active exploitation reported across 8 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Peaked 2d ago at 4 mentions (2026-08-21); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-08-20: 2Mentions · 2026-08-21: 4Mentions · 2026-08-28: 1Mentions · 2026-08-30: 1PoC Mentioned / Linked · 2026-08-28: 1Active Exploitation · 2026-08-20: 2Active Exploitation · 2026-08-21: 4Active Exploitation · 2026-08-28: 1Active Exploitation · 2026-08-30: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-30: 1Technical Details · 2026-08-20: 2Technical Details · 2026-08-21: 3Technical Details · 2026-08-28: 1Technical Details · 2026-08-30: 108-2008-2108-2808-30
Signal classification1 categories
Active Exploitation
8100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-202
Active Exploitation2
2026-08-214
Active Exploitation4
2026-08-281
Active Exploitation1
2026-08-301
Active Exploitation1
Full discourse8 posts
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    CVE-2026-77647 (CVSS 9.8) is an unauthenticated SPIP remote code execution flaw exploited in the wild. Update to SPIP 4.4.20 now. #SPIP #CVE202677647 #RCE #ExploitedInTheWild #CMS #WebSecurity https://securityonline.info/cve-2026-77647-spip-rce/

    Post summary

    CVE‑2026‑77647 is a critical, unauthenticated RCE in SPIP, actively exploited in the wild; the vendor has released an immediate patch to version 4.4.20.

    07026141.7K
    13.0K followersView on X
  • DFIR Lab@DFIR_Lab
    Active Exploitation

    🚨 CRITICAL: CVE-2026-77647 (CVSS 9.8) - SPIP &lt;4.4.20 allows unauthenticated RCE. ACTIVELY EXPLOITED in the wild since August 2026. Patch immediately! Flaw in PHP block identification + var_export handling. #CVE #PatchNow #ThreatIntel https://t.co/wvvVFEisi3

    Post summary

    CVE-2026-77647 is a critical, unauthenticated RCE affecting SPIP versions below 4.4.20, has been actively exploited in the wild since August 2026, and requires an immediate patch.

    0000137
    122 followersView on X
  • NewNormal Security@NewScanTeam
    Active Exploitation

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 21 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 Actively-exploited build of a self-hosted conferencing server — code execution and account takeover with no login (TrueConf CVE-2026-72530, CVE-2026-72529) 🔓 API guard that reads a different path than the router — a re-spelled URL skips it and hands over every message in a dev mail catcher, password resets included (Mailpit CVE-2026-67448) ⚡ CMS mis-reading PHP open tags in user-supplied content, exploited in the wild this month — unauthenticated code execution (SPIP CVE-2026-77647) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM

    Post summary

    The report highlights multiple CVEs that are actively exploited in the wild—code execution and account takeover in a conferencing server, misread PHP tags in a CMS, and a URL bypass in an API—without mentioning any patches or workarounds.

    0001037
    5 followersView on X
  • Alexander Leonov@leonov_av
    Active Exploitation

    🚨 August Linux Patch Wednesday: record 3,060 vulns (+52%); 3 exploited in the wild - Jenkins RCE CVE-2026-53435, WordPress CodeInj CVE-2026-60137, SPIP RCE CVE-2026-77647 + 127 with public exploits. #LinuxPatchWednesday #Linux #Vulristics ➡️ https://avleonov.com/2026/08/26/i138-august-linux-patch-wednesday/ https://t.co/Bx0OY5KDxl

    Post summary

    The August Linux Patch Wednesday report highlights 3,060 identified vulnerabilities, three of which—Jenkins, WordPress, and SPIP—have already been exploited in the wild, with 127 additional CVEs noted to have public exploit code.

    0000086
    1.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Active Exploitation

    CVE-2026-77647 SPIP Remote Code Execution In The Wild August 2026 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-77647

    Post summary

    The text announces that SPIP Remote Code Execution (CVE-2026-77647) has been actively exploited in the wild as of August 2026.

    00000109
    4.1K followersView on X
  • moton@moton
    Active Exploitation

    CVE-2026-77647: SPIP RCE Exploited in the Wild - https://securityonline.info/cve-2026-77647-spip-rce/

    Post summary

    CVE‑2026‑77647, a remote code execution flaw in SPIP, is reported as actively exploited in the wild, with a referenced article for more details.

    0000064
    753 followersView on X
  • Infoflowcloud@infoflowcloud
    Active Exploitation

    🚨*CVE* CVE-2026-77647 SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identifica… https://www.cve.org/CVERecord?id=CVE-2026-77647 ----- Traducción: CVE-2026-77647 SPI… https://infoflow.cloud`

    Post summary

    The CVE-2026-77647 vulnerability in SPIP allows unauthenticated remote code execution and has been reported as actively exploited in August 2026, yet no PoC, tool, patch, or debunking information is provided.

    0000052
    102 followersView on X
  • CVE@CVEnew
    Active Exploitation

    CVE-2026-77647 SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identifica… https://www.cve.org/CVERecord?id=CVE-2026-77647

    Post summary

    CVE-2026-77647 in SPIP enables remote code execution and was actively exploited in August 2026, but no PoC, exploit tool, or patch is mentioned in the text.

    00000977
    58.0K followersView on X

Explore more