logo

Total CMS Takeover: Movable Type Patches Critical 9.8 CVSS Perl RCE

ID: 3a97efe3-d208-5359-9f36-5c32259cae0d

STIX ID: report--3a97efe3-d208-5359-9f36-5c32259cae0d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-13

Date Updated: 2026-05-05

Author: Ddos

...
...

Six Apart published an urgent advisory for Movable Type describing two critical flaws in the Listing Framework: an RCE (CVE-2026-25776, CVSS 9.8) that can execute arbitrary Perl code and an SQL injection (CVE-2026-33088, CVSS 7.3) allowing arbitrary SQL commands. The issues affect Movable Type 6.0 and later; patches are available (9.0.7, 8.8.3, 8.0.10) and temporary mitigations include restricting access to mt.cgi and mt-data-api.cgi or disabling the Data API if unused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.