Exploitation reported elsewhere › SPIP
CVE-2026-77806
SPIP · CMS, e-commerce and websites
Exploitation reported by CERT-FR — not (yet) in CISA’s catalog
In brief
Level of evidence: CISA has not (yet) added it to its catalog of exploited vulnerabilities. The report comes from another official source, cited below.
First reported: August 21, 2026.
Brand and category: the site’s indicative classification, based on the vendor name given by CERT-FR.
Who reports it
- Reported by CERT-FR CERT-FR advisory CERTFR-2026-AVI-1063 of August 21, 2026 : Vulnérabilité dans SPIP (updated August 24, 2026)
Information reused under the Open Licence 2.0 (Etalab); the date of last update is shown for each advisory. This site is neither affiliated with nor endorsed by ANSSI.
What should I do?
Check whether you use this product. If so, apply the fix or workaround given by the vendor, first on devices exposed to the Internet.
Read the CERT-FR publication for affected versions and measures (in French).
If CISA adds it to its catalog, it will join the patch list with its instruction.
- CERT-FR advisory CERTFR-2026-AVI-1063 of August 21, 2026
- SPIP security advisories page (general page, not the advisory for this vulnerability)
- The vendor’s specific advisory is listed in the NVD references: CVE-2026-77806 on the NVD website.
Severity and activity
Vulnerability published: August 21, 2026.
Description
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.
Official description from the NVD, collected Sep 30, 2026. CVE® description © The MITRE Corporation.
Sources for this page
- CERT-FR: advisories and alerts (in French).
- NVD (NIST): CVSS severity, publication date, description, vendor references.
- CISA KEV catalog: the vulnerability is not (yet) in it.
- Brand and category: indicative classification by this site (method).