← back
CVE-2026-77647criticalobserved exploitationCWE-94

CVE-2026-77647

65Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.8epss 2.6%
from disclosure to weapon0 days
Published on NVDAug 20
metasploitAug 20
VulnCheckAug 20
exploitation probability
2.6%top 16% of all CVEs
observed exploitation
yesVulnCheck
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
SPIP · SPIP