Skip to content

Exploitation reported elsewhere › SPIP

Reported by CERT-FR

CVE-2026-77806

SPIP · CMS, e-commerce and websites

Exploitation reported by CERT-FR — not (yet) in CISA’s catalog

In brief

Level of evidence: CISA has not (yet) added it to its catalog of exploited vulnerabilities. The report comes from another official source, cited below.

First reported: August 21, 2026.

Brand and category: the site’s indicative classification, based on the vendor name given by CERT-FR.

Who reports it

Information reused under the Open Licence 2.0 (Etalab); the date of last update is shown for each advisory. This site is neither affiliated with nor endorsed by ANSSI.

What should I do?

Check whether you use this product. If so, apply the fix or workaround given by the vendor, first on devices exposed to the Internet.

Read the CERT-FR publication for affected versions and measures (in French).

If CISA adds it to its catalog, it will join the patch list with its instruction.

Severity and activity

9.8 / 10 CVSS severity: critical

Score from the NVD. Collected Sep 30, 2026.

Vulnerability published: August 21, 2026.

Description

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.

Official description from the NVD, collected Sep 30, 2026. CVE® description © The MITRE Corporation.

Sources for this page

  • CERT-FR: advisories and alerts (in French).
  • NVD (NIST): CVSS severity, publication date, description, vendor references.
  • CISA KEV catalog: the vulnerability is not (yet) in it.
  • Brand and category: indicative classification by this site (method).