Netlas.io[verified]@Netlas_ioActive Exploitation
CVE-2026-77806 enables unauthenticated remote code execution in SPIP; public exploit code in Metasploit is active, and the vulnerability is reported as being exploited in the wild.
dbugs[verified]@ptdbugsExploit
A PoC/exploit for CVE-2026-77806 has been released on GitHub, and the vulnerability—unauthenticated remote code execution in SPIP 4.4.21 and earlier—is said to have been actively exploited in the wild.
yousukezan[verified]@yousukezanActive Exploitation
CVE‑2026‑77806 is an unauthenticated RCE in SPIP CMS that has already been exploited in the wild (August 2026). A Metasploit module exists, and the vendor has released a patch in version 4.4.21; no workaround is available except upgrading.
EMILIA // SIGNAL[verified]@EmiliaSignalActive Exploitation
The text reports that CVE-2026-77806 is actively exploited in the wild, enabling unauthenticated remote code execution via a crafted HTTP header, and urges users to patch to SPIP 4.4.21.
Aretiq.AI[verified]@AretiqAIActive Exploitation
The bulletin reports that CVE-2026-77806 was exploited in the wild, but provides no PoC, patch, or detailed technical information.
ADK Cyber[verified]@ADKCyberActive Exploitation
SPIP CMS versions prior to 4.4.21 are vulnerable to unauthenticated RCE (CVE‑2026‑77806, CVSS 9.8) and have already been exploited in the wild; users are advised to review and patch affected instances.
Cybermalveillance.gouv.fr@cybervictimesDisclosure
The message announces a critical CVE (CVE-2026-77806) affecting SPIP and urges users to promptly update their CMS, but does not provide proof‑of‑concept, exploit code, active exploitation evidence, or detailed technical data.
pdnuclei-bot@pdnuclei_botDisclosure
The tweet announces CVE‑2026‑77806 as a critical unauthenticated remote code execution vulnerability affecting SPIP versions below 4.4.22, describes the flaw, and points to a detailed resource.