VORANT. Threat Intelligence Research Sign in Create a free account

Movable Type patches critical code injection flaws

routine vulnerability technology

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Two CVEs in Six Apart's Movable Type CMS allow arbitrary Perl code execution and SQL injection; patches and workarounds are available.

JPCERT/CC and IPA published JVN#91153973 detailing multiple vulnerabilities in Six Apart's Movable Type content management system, including a code injection flaw (CVE-2026-96408, CVSS 9.4) that could allow arbitrary Perl code execution, and a SQL injection flaw (CVE-2026-103668, CVSS 8.6) that could allow arbitrary SQL command execution. The advisory notes additional unspecified vulnerabilities were also fixed; defenders should consult the vendor's own release notes for full details.

Affected versions span the full current product line: Movable Type 9.2.1 and earlier (cloud-only 9.2 series), 9.0.9 and earlier (9.0 series, including Advanced), 8.8.5 and earlier, 8.0.12 and earlier, and the Premium editions (9.2.1, 9.0.9, and 2.17 and earlier). End-of-life versions (8.4, 7.x and earlier, Premium 1.x) are also affected but no longer supported with patches.

The advisory does not indicate active exploitation in the wild; it is a coordinated disclosure through Japan's Information Security Early Warning Partnership. Remediation is to update to the latest vendor release. Where immediate patching isn't possible, IPA recommends workarounds: removing or revoking execute permissions on mt-upgrade.cgi, mt-search.cgi, and mt-ftsearch.cgi (CGI deployments), or adding RestrictedPSGIApp directives for upgrade, new_search, and ft_search in mt-config.cgi (PSGI deployments, MT 6.2+, with ft_search requiring MT 6.2.4+).

Mentioned in this report

Vulnerabilities CVE-2026-103668CVE-2026-96408

Detection guidance

Movable Type Web Process Spawning Shell or Download Utility

ATT&CK T1059

Perl/PSGI/web server processes tied to Movable Type spawning a shell or download/recon tooling, consistent with post-exploitation of a Perl code injection flaw. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Movable Type Web Process Spawning Shell or Download Utility
description: Detects a Perl interpreter, PSGI server or web server process associated
  with Movable Type spawning a shell that runs download or reconnaissance commands.
  Consistent with post-exploitation of a Perl code injection flaw in the CMS (T1190
  leading to T1059).
tags:
- attack.execution
- attack.t1059
- attack.initial-access
- attack.t1190
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent_mt:
    ParentImage|endswith:
    - /perl
    - /starman
    - /plackup
    - /uwsgi
    ParentCommandLine|contains:
    - mt.psgi
    - movabletype
    - mt-
  selection_parent_web:
    ParentImage|endswith:
    - /httpd
    - /apache2
    - /nginx
    CurrentDirectory|contains:
    - /cgi-bin/mt
    - movabletype
  selection_child:
    Image|endswith:
    - /sh
    - /bash
    - /dash
    CommandLine|contains:
    - wget
    - curl
    - whoami
    - uname -a
    - /dev/tcp/
    - nc
    - base64 -d
    - chmod +x
  condition: 1 of selection_parent_* and selection_child
falsepositives:
- Administrators running Movable Type maintenance or deployment scripts that call
  curl or wget through a shell
- Custom Movable Type plugins that shell out to fetch remote resources
level: high
id: 398d20df-d1ae-5de6-96f8-0b3864832ad9
status: experimental
author: Vorant
references:
- https://www.ipa.go.jp/security/security-alert/2026/20261007-jvn.html

Request to Movable Type Upgrade CGI on Production Web Server

ATT&CK T1190

Web requests to mt-upgrade.cgi, the upgrade entry point named in the IPA workaround, which should be rarely reachable in production. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Request to Movable Type Upgrade CGI on Production Web Server
description: Detects successful-looking web requests to mt-upgrade.cgi, which IPA
  advises restricting or removing as a workaround for the Movable Type code injection
  and SQL injection flaws. Outside planned upgrades this endpoint should not be requested,
  so hits suggest probing or exploitation. Review volume per source IP when triaging.
tags:
- attack.initial-access
- attack.t1190
logsource:
  category: webserver
detection:
  selection:
    cs-uri-stem|endswith: /mt-upgrade.cgi
  filter_blocked:
    sc-status:
    - 403
    - 404
  condition: selection and not filter_blocked
falsepositives:
- Planned Movable Type upgrades run by administrators through the web upgrade wizard
- Authorized vulnerability scans of the CMS
level: medium
id: 4bd6856a-ccc0-57a2-9cdb-ed42bcf58cfa
status: experimental
author: Vorant
references:
- https://www.ipa.go.jp/security/security-alert/2026/20261007-jvn.html

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/20261007-jvn.html

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,868 reports from 149 sources, 447 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs