View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

SPIP Before 4.4.20 Hit by Unauthenticated RCE CVE-2026-77647

๐Ÿšจ ACTIVE EXPLOITATION

  • SPIP Before 4.4.20 Hit by Unauthenticated RCE CVE-2026-77647 CVE-2026-77647
    SPIP versions before 4.4.20 have been exploited for unauthenticated remote code execution.
    • SPIP installations running versions before 4.4.20 are affected.
    • CVE-2026-77647 allows unauthenticated remote attackers to execute arbitrary code.
    • The vulnerability was exploited in the wild in August 2026.
    • Exploitation requires no authentication and is remotely reachable.
      ๐Ÿ“Ž Coverage: thehackerwire.com ยท ๐Ÿ‘ via CVE ThreatInt, thehackerwire.com (discovered)

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

๐Ÿ”“ CVEs & KEV

  • CVE-2026-72843 โ€” CVSS 9.3 โ€” EverShop Critical Unauthenticated Account Takeover

  • CVE-2026-77645 โ€” CVSS 9.2 โ€” Critical Remote Code Execution (RCE) vulnerability reported in WindchillA cri...

  • CVE-2026-77646 โ€” CVSS 7.7 โ€” Server Side Request Forgery (SSRF) vulnerability reported in WindchillA Serve...

  • CVE-2026-49217 โ€” CVSS 7.5 โ€” Mailu missing authentication on PATCH /api/v1/token/<id>, which allows unauth...

  • CVE-2026-77113 โ€” CVSS 6.7 โ€” Path Traversal Vulnerability in apport-unpackPath traversal in apport-unpack ...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check