Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-77647 – Unauthenticated Remote Code Execution – SPIP before 4.4.20

Be the first to know when new zero-days emerge:

Summary

CVE-2026-77647 is a critical, pre-authentication remote code execution vulnerability affecting all versions of SPIP prior to 4.4.20. The flaw is caused by incorrect identification of <?php blocks combined with a mishandling in var_export when a '<' character is present, allowing an unauthenticated attacker to inject and execute arbitrary PHP code. The vulnerability has a CVSS v3.1 score of 9.8 (Critical) and has reportedly been exploited in the wild since August 2026.

Technical details

  • Root cause: Incorrect identification of <?php code blocks combined with var_export‘s mishandling of certain inputs, specifically the presence of a '<' character, which allows attacker-controlled data to be interpreted and executed as PHP code.
  • Trigger conditions: No authentication or user interaction is required; the vulnerable code path is reachable pre-authentication, described by the vendor as exploitable "without conditions" and bypassing SPIP’s security screen.
  • Attack vector: Network — an attacker sends a crafted request to a publicly reachable SPIP installation.
  • Impact: Full compromise of confidentiality, integrity, and availability via arbitrary PHP code execution on the affected server.

Affected software

  • SPIP versions 0 through 4.4.19 (all versions prior to 4.4.20)

Severity

  • CVSS v3.1 Base Score: 9.8 (Critical)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Mitigation and recommended actions

  • Immediate: Upgrade to SPIP 4.4.20 or later, either by downloading the release directly or via spip_loader version 7.0.0 or later.
  • If patching cannot be performed immediately: No official workaround has been published; given active in-the-wild exploitation, restrict or block public access to the SPIP installation until the upgrade can be completed, and monitor logs for suspicious requests.
  • Distribution-specific packages (e.g., Debian) have also released patched builds — apply OS-level package updates where SPIP was installed via a distribution repository.

How IONIX identifies potentially affected assets

IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.

  • Named response header composed-by: value matching SPIP <version> @
  • Named response header x-spip-cache: presence of the header
  • <meta name="generator"> content: value matching SPIP <version>

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge