DFIR Lab[verified]@DFIR_LabActive Exploitation
CVE-2026-77647 is a critical, unauthenticated RCE affecting SPIP versions below 4.4.20, has been actively exploited in the wild since August 2026, and requires an immediate patch.
NewNormal Security[verified]@NewScanTeamActive Exploitation
The report highlights multiple CVEs that are actively exploited in the wild—code execution and account takeover in a conferencing server, misread PHP tags in a CMS, and a URL bypass in an API—without mentioning any patches or workarounds.
Daily CyberSecurity@Daily_CyberSecActive Exploitation
CVE‑2026‑77647 is a critical, unauthenticated RCE in SPIP, actively exploited in the wild; the vendor has released an immediate patch to version 4.4.20.
Alexander Leonov@leonov_avActive Exploitation
The August Linux Patch Wednesday report highlights 3,060 identified vulnerabilities, three of which—Jenkins, WordPress, and SPIP—have already been exploited in the wild, with 127 additional CVEs noted to have public exploit code.
Vulmon Vulnerability Feed@VulmonFeedsActive Exploitation
The text announces that SPIP Remote Code Execution (CVE-2026-77647) has been actively exploited in the wild as of August 2026.
moton@motonActive Exploitation
CVE‑2026‑77647, a remote code execution flaw in SPIP, is reported as actively exploited in the wild, with a referenced article for more details.
Infoflowcloud@infoflowcloudActive Exploitation
The CVE-2026-77647 vulnerability in SPIP allows unauthenticated remote code execution and has been reported as actively exploited in August 2026, yet no PoC, tool, patch, or debunking information is provided.
CVE@CVEnewActive Exploitation
CVE-2026-77647 in SPIP enables remote code execution and was actively exploited in August 2026, but no PoC, exploit tool, or patch is mentioned in the text.