Movable Type patches critical code injection flaws
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Two CVEs in Six Apart's Movable Type CMS allow arbitrary Perl code execution and SQL injection; patches and workarounds are available.
JPCERT/CC and IPA published JVN#91153973 detailing multiple vulnerabilities in Six Apart's Movable Type content management system, including a code injection flaw (CVE-2026-96408, CVSS 9.4) that could allow arbitrary Perl code execution, and a SQL injection flaw (CVE-2026-103668, CVSS 8.6) that could allow arbitrary SQL command execution. The advisory notes additional unspecified vulnerabilities were also fixed; defenders should consult the vendor's own release notes for full details.
Affected versions span the full current product line: Movable Type 9.2.1 and earlier (cloud-only 9.2 series), 9.0.9 and earlier (9.0 series, including Advanced), 8.8.5 and earlier, 8.0.12 and earlier, and the Premium editions (9.2.1, 9.0.9, and 2.17 and earlier). End-of-life versions (8.4, 7.x and earlier, Premium 1.x) are also affected but no longer supported with patches.
The advisory does not indicate active exploitation in the wild; it is a coordinated disclosure through Japan's Information Security Early Warning Partnership. Remediation is to update to the latest vendor release. Where immediate patching isn't possible, IPA recommends workarounds: removing or revoking execute permissions on mt-upgrade.cgi, mt-search.cgi, and mt-ftsearch.cgi (CGI deployments), or adding RestrictedPSGIApp directives for upgrade, new_search, and ft_search in mt-config.cgi (PSGI deployments, MT 6.2+, with ft_search requiring MT 6.2.4+).
Mentioned in this report
Detection guidance
Movable Type Web Process Spawning Shell or Download Utility
Perl/PSGI/web server processes tied to Movable Type spawning a shell or download/recon tooling, consistent with post-exploitation of a Perl code injection flaw. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Movable Type Web Process Spawning Shell or Download Utility
description: Detects a Perl interpreter, PSGI server or web server process associated
with Movable Type spawning a shell that runs download or reconnaissance commands.
Consistent with post-exploitation of a Perl code injection flaw in the CMS (T1190
leading to T1059).
tags:
- attack.execution
- attack.t1059
- attack.initial-access
- attack.t1190
logsource:
category: process_creation
product: linux
detection:
selection_parent_mt:
ParentImage|endswith:
- /perl
- /starman
- /plackup
- /uwsgi
ParentCommandLine|contains:
- mt.psgi
- movabletype
- mt-
selection_parent_web:
ParentImage|endswith:
- /httpd
- /apache2
- /nginx
CurrentDirectory|contains:
- /cgi-bin/mt
- movabletype
selection_child:
Image|endswith:
- /sh
- /bash
- /dash
CommandLine|contains:
- wget
- curl
- whoami
- uname -a
- /dev/tcp/
- nc
- base64 -d
- chmod +x
condition: 1 of selection_parent_* and selection_child
falsepositives:
- Administrators running Movable Type maintenance or deployment scripts that call
curl or wget through a shell
- Custom Movable Type plugins that shell out to fetch remote resources
level: high
id: 398d20df-d1ae-5de6-96f8-0b3864832ad9
status: experimental
author: Vorant
references:
- https://www.ipa.go.jp/security/security-alert/2026/20261007-jvn.html
Request to Movable Type Upgrade CGI on Production Web Server
Web requests to mt-upgrade.cgi, the upgrade entry point named in the IPA workaround, which should be rarely reachable in production. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Request to Movable Type Upgrade CGI on Production Web Server
description: Detects successful-looking web requests to mt-upgrade.cgi, which IPA
advises restricting or removing as a workaround for the Movable Type code injection
and SQL injection flaws. Outside planned upgrades this endpoint should not be requested,
so hits suggest probing or exploitation. Review volume per source IP when triaging.
tags:
- attack.initial-access
- attack.t1190
logsource:
category: webserver
detection:
selection:
cs-uri-stem|endswith: /mt-upgrade.cgi
filter_blocked:
sc-status:
- 403
- 404
condition: selection and not filter_blocked
falsepositives:
- Planned Movable Type upgrades run by administrators through the web upgrade wizard
- Authorized vulnerability scans of the CMS
level: medium
id: 4bd6856a-ccc0-57a2-9cdb-ed42bcf58cfa
status: experimental
author: Vorant
references:
- https://www.ipa.go.jp/security/security-alert/2026/20261007-jvn.html
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://www.ipa.go.jp/security/security-alert/2026/20261007-jvn.html
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,868 reports from 149 sources, 447 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs