CVE-2026-77647
SPIP90/100
exploitation likelihood
CVSS9.8
EPSS2.6%
VulnCheck KEVEXPLOITED
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.
Listed in VulnCheck KEV (confirmed exploited in the wild) · CVSS base 9.8
Public PoC / Exploit
No public PoC/exploit references indexed yet (Exploit-DB / nuclei). Newly-disclosed CVEs often have none — exploit publication lags disclosure.
References2