Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-77647: SPIP before 4.4.20 lets attackers run code

CVE-2026-77647 · published 14 days ago
Summary

Websites using SPIP versions older than 4.4.20 can be accessed by anyone on the internet who can then cause the server to run their own programs. This happens because the software misinterprets certain code blocks, allowing malicious input to be executed. Upgrade SPIP to version 4.4.20 or later, or apply the provided security patch, to stop this risk.

What to do
  • Update debian spip to version 4.4.20+dfsg-0+deb13u1.
  • Update spip spip to version 4.4.20 or later.
Affected software
Ecosystem VendorProductAffected versions
– spip spip < 4.4.20
Debian:11 debian spip All versions
Debian:13 debian spip < 4.4.20+dfsg-0+deb13u1
Fix: upgrade to 4.4.20+dfsg-0+deb13u1
Debian:14 debian spip All versions
Original advisory text
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_e...
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 3%
Type
CWE-94Code Injection
Timeline
Published20 Aug 2026
Updated2 Sep 2026
First seen20 Aug 2026
Sources
CVE-2026-77647 · MITRE
Monitor software like this
Free during beta