# SPIP CMS patches critical RCE flaw

Published: 2026-09-03 · Severity: routine · Sectors: technology, media
Canonical: https://vorant.io/reports/7685206b-5fa0-5153-8b0c-b9b8554eb410/spip-cms-patches-critical-rce-flaw

> CERT-FR warns that SPIP versions before 4.4.23 contain flaws enabling remote code execution and privilege escalation.

CERT-FR issued an advisory regarding multiple vulnerabilities in SPIP, an open-source content management system, affecting all versions prior to 4.4.23. The vulnerabilities can be exploited by an attacker to achieve remote code execution and privilege escalation on affected systems. No specific technical details of the exploitation chain were disclosed in the advisory.

The SPIP editorial team released a security bulletin on 02 September 2026 alongside the patched version 4.4.23. Administrators running SPIP-based websites are advised to consult the vendor's security bulletin and apply the available patches promptly to mitigate the risk of remote compromise. There is no indication in this advisory of active exploitation in the wild; the severity relates to the potential impact (RCE and privilege escalation) rather than confirmed attacker activity.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1109

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7685206b-5fa0-5153-8b0c-b9b8554eb410/spip-cms-patches-critical-rce-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
