CVE-2026-77647
SPIP Arbitrary Code Execution Vulnerability
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
SPIP, a content management system, has a critical vulnerability allowing unauthenticated remote code execution. This issue, related to incorrect identification of PHP code blocks and mishandling of specific characters by `var_export`, has been exploited in the wild. As SPIP is often a public-facing web application, thi