CVE-2026-77806Active Exploitation

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 10 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 8 observed days

What's happening

  • Active exploitation reported across 10 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 12 signals
  • Disclosure: 3 classified signals
  • Peaked 6d ago at 4 mentions (2026-08-22); latest day: 2
  • 14 total mentions across 8 days

Deep dive

Activity timeline14 mentions / 8d
01234Mentions · 2026-08-21: 2Mentions · 2026-08-22: 4Mentions · 2026-08-23: 1Mentions · 2026-08-24: 2Mentions · 2026-08-25: 1Mentions · 2026-08-26: 1Mentions · 2026-08-27: 1Mentions · 2026-08-31: 2PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-22: 2PoC Mentioned / Linked · 2026-08-24: 1PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-31: 1Exploit Tool / Code · 2026-08-21: 1Exploit Tool / Code · 2026-08-22: 1Exploit Tool / Code · 2026-08-24: 1Exploit Tool / Code · 2026-08-25: 1Active Exploitation · 2026-08-21: 2Active Exploitation · 2026-08-22: 4Active Exploitation · 2026-08-23: 1Active Exploitation · 2026-08-24: 2Active Exploitation · 2026-08-25: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-22: 2Patch / Workaround · 2026-08-27: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-22: 4Technical Details · 2026-08-23: 1Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 1Technical Details · 2026-08-26: 1Technical Details · 2026-08-31: 208-2108-2208-2308-2408-2508-2608-2708-31
Signal classification4 categories
Active Exploitation
964.3%
Disclosure
321.4%
Exploit
17.1%
General
17.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-08-212
Active Exploitation2
2026-08-224
Active Exploitation4
2026-08-231
Active Exploitation1
2026-08-242
Active Exploitation2
2026-08-251
Exploit1
2026-08-261
Disclosure1
2026-08-271
Disclosure1
2026-08-312
Disclosure1General1
Full discourse14 posts
  • Cybermalveillance.gouv.fr@cybervictimes
    Disclosure

    🔴 [#AlerteCyber] Faille de sécurité critique dans #SPIP ⚠️ Risques : Espionnage, vol, modification, destruction de données 🛡️ #Particuliers #Entreprises #CollTerr #Associations : Mettez à jour votre #CMS sans tarder ! CVE-2026-77806 Plus d'infos👇 https://www.cybermalveillance.gouv.fr/tous-nos-contenus/actualites/alertecyber-faille-de-securite-critique-dans-spip-202608

    Post summary

    The message announces a critical CVE (CVE-2026-77806) affecting SPIP and urges users to promptly update their CMS, but does not provide proof‑of‑concept, exploit code, active exploitation evidence, or detailed technical data.

    71721715.6K
    46.4K followersView on X
  • Netlas.io@Netlas_io
    Active Exploitation

    CVE-2026-77806: Unauthenticated RCE in SPIP with public exploit and active exploitation, 9.8 rating ‍🔥 A recently disclosed vulnerability in SPIP allows unauthenticated remote attackers to execute arbitrary code. Public exploit code has been added to the Metasploit framework. This vulnerability is being actively exploited in the wild! 👉 https://nt.ls/SeHVc

    Post summary

    CVE-2026-77806 enables unauthenticated remote code execution in SPIP; public exploit code in Metasploit is active, and the vulnerability is reported as being exploited in the wild.

    09022121.9K
    7.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-77806 - critical 🚨 SPIP < 4.4.22 - Unauthenticated RCE > SPIP < 4.4.21 contains a remote code execution caused by mishandling of the X-Spip-Fi... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-77806 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE‑2026‑77806 as a critical unauthenticated remote code execution vulnerability affecting SPIP versions below 4.4.22, describes the flaw, and points to a detailed resource.

    030168729
    1.3K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-77806 Vendor: SPIP Product: SPIP Description: SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel. Link: https://github.com/cuteecat/cve-2026-77806 #dbugs_vuln

    Post summary

    A PoC/exploit for CVE-2026-77806 has been released on GitHub, and the vulnerability—unauthenticated remote code execution in SPIP 4.4.21 and earlier—is said to have been actively exploited in the wild.

    0001441.1K
    3.6K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    SPIP CMSで、認証なしに任意コード実行が可能な重大な脆弱性CVE-2026-77806が公開された。全バージョンの4.4.21未満が影響を受け、2026年8月には実際の悪用が確認され、公開Exploitも登場している。 問題はHTTPリクエストヘッダーX-Spip-Filtreの処理にあり、analyse_resultat_skelルーチンで攻撃者が指定した入力がコード実行へ到達する。単純なHTTPヘッダーを送るだけで発火でき、ログインは不要である。SPIPは4.4.21を重大なセキュリティ更新として公開し、この版で修正した。CVE情報では2026年8月の実悪用が記録され、Metasploitにも公開Exploitモジュールが追加された。記事では有効な回避策はないとして、4.4.21への更新を求めている。 https://securityonline.info/cve-2026-77806-spip-unauthenticated-rce/

    Post summary

    CVE‑2026‑77806 is an unauthenticated RCE in SPIP CMS that has already been exploited in the wild (August 2026). A Metasploit module exists, and the vendor has released a patch in version 4.4.21; no workaround is available except upgrading.

    0501022.4K
    15.9K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    CVE-2026-77806 (CVSS 9.8) is a SPIP unauthenticated RCE exploited in the wild, with public exploit code now available. Update to SPIP 4.4.21 now. #CVE202677806 #SPIP #RCE #ExploitedInTheWild #Metasploit #CMS http://securityonline.info/cve-2026-77806-spip-unauthenticated-rce/

    Post summary

    CVE‑2026‑77806 is a high‑severity unauthenticated RCE in SPIP that is already being exploited in the wild, with public exploit code and a recent patch (SPIP 4.4.21) available.

    00043615
    13.0K followersView on X
  • EMILIA // SIGNAL@EmiliaSignal
    Active Exploitation

    A critical SPIP flaw is already being exploited in the wild. CVE-2026-77806 gives unauthenticated attackers remote code execution through a crafted HTTP header. SPIP’s built-in security screen doesn’t stop it. Update to 4.4.21.

    Post summary

    The text reports that CVE-2026-77806 is actively exploited in the wild, enabling unauthenticated remote code execution via a crafted HTTP header, and urges users to patch to SPIP 4.4.21.

    1002072
    89 followersView on X
  • Halil Deniz@denizhalilT
    Disclosure

    🚨 Critical Security Alert! Unauthenticated RCE in SPIP (<4.4.22) via CVE-2026-77806 allows attackers to execute OS commands using custom X-Spip-Filtre headers. Read the full technical breakdown here: https://denizhalil.com/2026/08/31/cve-2026-77806-spip-unauthenticated-rce-analysis/ #CyberSecurity #Infosec #CVE202677806 https://t.co/hK2OZDXN1m

    Post summary

    The post announces an unauthenticated remote code execution vulnerability in SPIP (CVE-2026-77806), provides a link to a technical analysis, but does not mention active exploitation, patches, or a separate PoC.

    0001064
    33 followersView on X
  • Aretiq.AI@AretiqAI
    Active Exploitation

    ARETIQ Daily Vulnerability Bulletin — August 21, 2026 🔴 CRITICAL: CVE-2026-77806 (spip/spip) AAS 13.9 — exploited ITW 16 vulnerabilities — CRITICAL: 1, HIGH: 15 Full bulletin: https://aretiq.ai/bulletins/2026-08-21/

    Post summary

    The bulletin reports that CVE-2026-77806 was exploited in the wild, but provides no PoC, patch, or detailed technical information.

    0001092
    227 followersView on X
  • David@ComprendreLIA
    General

    @Frenchbreaches "Selon le syndicat, cette cyberattaque intervient après le piratage massif des serveurs de l’Éducation nationale, mais serait d’une nature différente." Je pense connaitre la faille : CVE-2026-77806, affectant toutes les versions de SPIP antérieures à la version 4.4.21. 😉

    Post summary

    The tweet identifies CVE-2026-77806 as affecting SPIP versions before 4.4.21, but provides no evidence of exploitation, PoC, or patch information.

    00000139
    311 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Active Exploitation

    CVE-2026-77806 Actalis Digital Certificate System Tier 1: authentication bypass in certificate authority infrastructure with confirmed in-the-wild exploitation Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-08-21/TIER_1_CVE-2026-77806.md #CyberSecurity #IdentitySecurity #VulnerabilityManagement

    Post summary

    CVE‑2026‑77806 is an authentication bypass in Actalis Digital Certificate System’s CA infrastructure that has confirmed in‑the‑wild exploitation, as highlighted in the Alan Turing Institute report.

    0000056
    59 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Active Exploitation

    Recent CVEs (e.g., CVE-2026-77806, CVE-2026-69836) are actively exploited, impacting network security & potentially compromising data in transit. DNS hijacking, as seen with CubePilot, also poses a critical threat to integrity. #Cybersecurity #News #Vulnerabilities

    Post summary

    The post reports that CVE-2026-77806 and CVE-2026-69836 are being actively exploited, with DNS hijacking posing a threat to data integrity. No patches or exploit details are provided.

    0000052
    17 followersView on X
  • ADK Cyber@ADKCyber
    Active Exploitation

    SPIP CMS before 4.4.21 vulnerable to unauthenticated RCE (CVE-2026-77806, CVSS 9.8) already exploited in the wild. Review your instances. http://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/exmalHyaEI

    Post summary

    SPIP CMS versions prior to 4.4.21 are vulnerable to unauthenticated RCE (CVE‑2026‑77806, CVSS 9.8) and have already been exploited in the wild; users are advised to review and patch affected instances.

    0000032
    93 followersView on X
  • moton@moton
    Active Exploitation

    CVE-2026-77806: SPIP Unauthenticated RCE Exploited in the Wild as Public Exploit Lands - https://securityonline.info/cve-2026-77806-spip-unauthenticated-rce/

    Post summary

    SecurityOnline reports that CVE-2026-77806, an unauthenticated RCE in SPIP, is actively exploited in the wild, with a public exploit now available.

    0000081
    753 followersView on X

Explore more