# Movable Type CMS RCE flaw actively exploited

Published: 2021-12-15 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/b5c76916-a4eb-5361-ac48-cfe08b96a813/movable-type-cms-rce-flaw-actively-exploited

> An OS command injection vulnerability in Movable Type's XMLRPC API is being actively exploited in the wild, and initial patches proved incomplete.

IPA (Japan's information security agency) issued an alert regarding a critical OS command injection vulnerability in the XMLRPC API of Six Apart's Movable Type CMS, affecting all versions from 4.0 onward, including end-of-life releases. The flaw allows a remote, unauthenticated attacker to execute arbitrary OS commands on the underlying server, and the derivative product PowerCMS is also affected.

As of November 5, 2021, IPA confirmed active exploitation of this vulnerability in the wild, prompting urgent calls for organizations to apply vendor patches or mitigations immediately. On December 16, 2021, Six Apart disclosed that the fix released on October 20, 2021 was insufficient, requiring further remediation. IPA recommends applying updated patches from the vendor or, where patching is not immediately possible, applying a workaround to the mt-config.cgi configuration file to reduce risk.

Given the CVSS v3 base score of 9.8 (critical) and confirmed real-world exploitation against a widely used CMS platform, affected organizations should prioritize patching or mitigation without delay, particularly given the initial patch's incomplete remediation.

## Mentioned in this report

- Vulnerabilities: CVE-2021-20837 (templated)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20211020-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b5c76916-a4eb-5361-ac48-cfe08b96a813/movable-type-cms-rce-flaw-actively-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
