Post
Suriq - Always on Watch
suriq.io
did:plc:6vjp7fbgz5ductueireifliv
🔴 EXPLOITED
SPIP, a widely used open-source website system, has a critical flaw (CVE-2026-77806, CVSS 9.8) that lets anyone run commands on the server with no login. It's being exploited now.
Sites patched only to 4.4.20 are still exposed.
Fix: update to SPIP 4.4.21.
https://suriq.io/blog/spip-unauthenticated-rce-cve-2026-77806
2026-08-21T14:18:33.063Z