# Movable Type patches critical code injection flaws

Published: 2026-10-06 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/28cdf2f9-36f0-5dfb-bd88-4ffc714367e2/movable-type-patches-critical-code-injection-flaws

> Two CVEs in Six Apart's Movable Type CMS allow arbitrary Perl code execution and SQL injection; patches and workarounds are available.

JPCERT/CC and IPA published JVN#91153973 detailing multiple vulnerabilities in Six Apart's Movable Type content management system, including a code injection flaw (CVE-2026-96408, CVSS 9.4) that could allow arbitrary Perl code execution, and a SQL injection flaw (CVE-2026-103668, CVSS 8.6) that could allow arbitrary SQL command execution. The advisory notes additional unspecified vulnerabilities were also fixed; defenders should consult the vendor's own release notes for full details.

Affected versions span the full current product line: Movable Type 9.2.1 and earlier (cloud-only 9.2 series), 9.0.9 and earlier (9.0 series, including Advanced), 8.8.5 and earlier, 8.0.12 and earlier, and the Premium editions (9.2.1, 9.0.9, and 2.17 and earlier). End-of-life versions (8.4, 7.x and earlier, Premium 1.x) are also affected but no longer supported with patches.

The advisory does not indicate active exploitation in the wild; it is a coordinated disclosure through Japan's Information Security Early Warning Partnership. Remediation is to update to the latest vendor release. Where immediate patching isn't possible, IPA recommends workarounds: removing or revoking execute permissions on mt-upgrade.cgi, mt-search.cgi, and mt-ftsearch.cgi (CGI deployments), or adding RestrictedPSGIApp directives for upgrade, new_search, and ft_search in mt-config.cgi (PSGI deployments, MT 6.2+, with ft_search requiring MT 6.2.4+).

## Mentioned in this report

- Vulnerabilities: CVE-2026-103668, CVE-2026-96408

## Detection guidance (public sample)

### Movable Type Web Process Spawning Shell or Download Utility

ATT&CK: T1059

Perl/PSGI/web server processes tied to Movable Type spawning a shell or download/recon tooling, consistent with post-exploitation of a Perl code injection flaw. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Movable Type Web Process Spawning Shell or Download Utility
description: Detects a Perl interpreter, PSGI server or web server process associated
  with Movable Type spawning a shell that runs download or reconnaissance commands.
  Consistent with post-exploitation of a Perl code injection flaw in the CMS (T1190
  leading to T1059).
tags:
- attack.execution
- attack.t1059
- attack.initial-access
- attack.t1190
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent_mt:
    ParentImage|endswith:
    - /perl
    - /starman
    - /plackup
    - /uwsgi
    ParentCommandLine|contains:
    - mt.psgi
    - movabletype
    - mt-
  selection_parent_web:
    ParentImage|endswith:
    - /httpd
    - /apache2
    - /nginx
    CurrentDirectory|contains:
    - /cgi-bin/mt
    - movabletype
  selection_child:
    Image|endswith:
    - /sh
    - /bash
    - /dash
    CommandLine|contains:
    - wget
    - curl
    - whoami
    - uname -a
    - /dev/tcp/
    - nc
    - base64 -d
    - chmod +x
  condition: 1 of selection_parent_* and selection_child
falsepositives:
- Administrators running Movable Type maintenance or deployment scripts that call
  curl or wget through a shell
- Custom Movable Type plugins that shell out to fetch remote resources
level: high
id: 398d20df-d1ae-5de6-96f8-0b3864832ad9
status: experimental
author: Vorant
references:
- https://www.ipa.go.jp/security/security-alert/2026/20261007-jvn.html
```

### Request to Movable Type Upgrade CGI on Production Web Server

ATT&CK: T1190

Web requests to mt-upgrade.cgi, the upgrade entry point named in the IPA workaround, which should be rarely reachable in production. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Request to Movable Type Upgrade CGI on Production Web Server
description: Detects successful-looking web requests to mt-upgrade.cgi, which IPA
  advises restricting or removing as a workaround for the Movable Type code injection
  and SQL injection flaws. Outside planned upgrades this endpoint should not be requested,
  so hits suggest probing or exploitation. Review volume per source IP when triaging.
tags:
- attack.initial-access
- attack.t1190
logsource:
  category: webserver
detection:
  selection:
    cs-uri-stem|endswith: /mt-upgrade.cgi
  filter_blocked:
    sc-status:
    - 403
    - 404
  condition: selection and not filter_blocked
falsepositives:
- Planned Movable Type upgrades run by administrators through the web upgrade wizard
- Authorized vulnerability scans of the CMS
level: medium
id: 4bd6856a-ccc0-57a2-9cdb-ed42bcf58cfa
status: experimental
author: Vorant
references:
- https://www.ipa.go.jp/security/security-alert/2026/20261007-jvn.html
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/20261007-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/28cdf2f9-36f0-5dfb-bd88-4ffc714367e2/movable-type-patches-critical-code-injection-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
