Total CMS Takeover: Movable Type Patches Critical 9.8 CVSS Perl RCE
ID: 3a97efe3-d208-5359-9f36-5c32259cae0d
STIX ID: report--3a97efe3-d208-5359-9f36-5c32259cae0d
Feed Name: securityonline.info
Threat Score
Six Apart published an urgent advisory for Movable Type describing two critical flaws in the Listing Framework: an RCE (CVE-2026-25776, CVSS 9.8) that can execute arbitrary Perl code and an SQL injection (CVE-2026-33088, CVSS 7.3) allowing arbitrary SQL commands. The issues affect Movable Type 6.0 and later; patches are available (9.0.7, 8.8.3, 8.0.10) and temporary mitigations include restricting access to mt.cgi and mt-data-api.cgi or disabling the Data API if unused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
