Movable Type CMS RCE flaw actively exploited
An OS command injection vulnerability in Movable Type's XMLRPC API is being actively exploited in the wild, and initial patches proved incomplete.
IPA (Japan's information security agency) issued an alert regarding a critical OS command injection vulnerability in the XMLRPC API of Six Apart's Movable Type CMS, affecting all versions from 4.0 onward, including end-of-life releases. The flaw allows a remote, unauthenticated attacker to execute arbitrary OS commands on the underlying server, and the derivative product PowerCMS is also affected.
As of November 5, 2021, IPA confirmed active exploitation of this vulnerability in the wild, prompting urgent calls for organizations to apply vendor patches or mitigations immediately. On December 16, 2021, Six Apart disclosed that the fix released on October 20, 2021 was insufficient, requiring further remediation. IPA recommends applying updated patches from the vendor or, where patching is not immediately possible, applying a workaround to the mt-config.cgi configuration file to reduce risk.
Given the CVSS v3 base score of 9.8 (critical) and confirmed real-world exploitation against a widely used CMS platform, affected organizations should prioritize patching or mitigation without delay, particularly given the initial patch's incomplete remediation.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20211020-jvn.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free