Movable Type CMS hit by critical RCE flaw
Movable Type CMS has a critical code injection flaw (CVSS 9.8) and an SQL injection bug affecting current and many end-of-life versions.
IPA published a JVN advisory disclosing two vulnerabilities in Six Apart's Movable Type content management system: a critical code injection flaw (CVE-2026-25776, CVSS 9.8) allowing arbitrary Perl code execution, and an SQL injection vulnerability (CVE-2026-33088, CVSS 7.3) allowing arbitrary SQL command execution. Both flaws stem from the listing framework used in the admin interface and from the Data API component.
The advisory covers a broad range of currently supported product lines (Movable Type 8.0–9.1, Advanced, Premium, and Premium Advanced Edition) as well as multiple end-of-life versions (5.1, 5.2, 6.x, 7, 8.4, and Premium 1.x) that remain affected due to shared use of the listing framework or Data API. As a mitigation for Data API-based attacks, the vendor recommends disabling the Data API by removing mt-data-api.cgi or restricting access via environment variables. Users are urged to update to the latest version; no in-the-wild exploitation is reported at this time.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2026/20260408-jvn.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free