SPIP issued back-to-back critical security updates after disclosing a pre-authentication remote code execution flaw that can be exploited against public-facing sites through the X-Spip-Filtre HTTP header. The project first released SPIP 4.4.20 to address a universally exploitable issue affecting all versions, then followed with SPIP 4.4.21 after determining that version 4.4.20 itself remained vulnerable. SPIP said the bug was reported anonymously via ANSSI, warned that exploitation attempts had already been observed in the wild, and stressed that the platform’s security screen does not mitigate the issue.
The vulnerability is tracked as CVE-2026-77806 and affects SPIP versions before 4.4.21, with a CVSS 3.1 score reflecting critical impact (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Rapid7 also added a Metasploit module for related exploitation of the X-Spip-Filtre mechanism, describing unauthenticated code execution via function-call injection in SPIP’s template engine and command execution through a crafted POST request. Administrators were urged to update immediately to SPIP 4.4.21, with SPIP recommending upgrades via spip_loader 7.0.0.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-21, MITRE received CVE-2026-77806 for a critical SPIP remote code execution vulnerability affecting versions before 4.4.21. The CVE describes unauthenticated code execution via mishandling of the X-Spip-Filtre header in analyse_resultat_skel and notes exploitation in the wild in August 2026.
On 2026-08-20, SPIP released version 4.4.21 as a critical security update to fix a universally exploitable pre-authentication remote code execution vulnerability affecting SPIP 4.4.20. SPIP again warned that the flaw was not blocked by its security screen and that exploitation attempts had already been seen in the wild.
On 2026-08-17, a Rapid7 Metasploit Framework pull request added an unauthenticated SPIP remote code execution module targeting the X-Spip-Filtre issue. The module documentation identifies SPIP 4.4.20 as affected and 4.4.21 as the fix, and describes exploitation through function-call injection in analyse_resultat_skel().
On 2026-08-17, SPIP released version 4.4.20 as a critical security update for a universally exploitable pre-authentication remote code execution vulnerability affecting all SPIP versions. SPIP said the flaw was reported anonymously via ANSSI, was not mitigated by the SPIP security screen, and exploitation attempts had already been observed in the wild.
The Metasploit module for the SPIP X-Spip-Filtre unauthenticated RCE sets the vulnerability disclosure date to 2026-08-20. The module references the SPIP 4.4.21 security update and associates the exploit with CVE-2026-77647.
An Automag.be administrator identified as Bob reported that the site suffered a malicious attack sometime between an update performed in April and the vulnerability's discovery in August. The report is presented in the context of the actively exploited SPIP pre-authentication RCE.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecsirt.bj
Open sourcecvefeed.io
Open sourceblog.spip.net
Open sourceblog.spip.net
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.