CVE-2026-25776Disclosure(sixapart / movable_type)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sixapart movable_type systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • movable_type

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-04-08); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
movable_type

3 versions affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-04-08: 3Mentions · 2026-04-09: 1Mentions · 2026-04-11: 1Mentions · 2026-04-12: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-08: 3Technical Details · 2026-04-09: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-15: 104-0804-0904-1104-1204-15
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-083
Disclosure3
2026-04-091
General1
2026-04-111
Disclosure1
2026-04-121
Disclosure1
2026-04-151
Disclosure1
Full discourse7 posts
  • Mr.Rabbit@01ra66it
    Disclosure

    【Movable Typeにおける複数の脆弱性】 JVNが公表した Movable Type の脆弱性は、4月15日時点でもかなり重い継続監視案件です。CVE-2026-25776 はコードインジェクション、CVE-2026-33088 は SQL インジェクションで、現行版だけでなく EOL 版まで広く影響します。日本では自治体、学校、企業の対外サイトで長期運用されているケースが多く、更新停滞環境を狙われやすい構図です。 特に厄介なのは、管理画面や Data API を含む運用面で刺さることです。表に出るトップページだけ見て安心していると、裏側の管理機能が穴になる。古い版では修正版が出ないため、運用停止・制限・更改を含めた判断が必要になります。 防御側は、Movable Type の有無、版数、Data API 利用有無、委託先保守の状態を即時確認したいところです。すぐ更新できない環境は、少なくとも回避策と公開面の絞り込みを先に進めるべきです。 #MovableType #JVN #RCE #SQLi #CMS #脆弱性対策 #WebSecurity https://jvn.jp/jp/JVN66473735/index.html

    Post summary

    The post announces new high‑severity vulnerabilities (CVE‑2026‑25776 and CVE‑2026‑33088) in Movable Type, detailing their types and affected versions without providing PoC, exploit code, or patch information.

    00012282
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25776 Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script. https://www.cve.org/CVERecord?id=CVE-2026-25776

    Post summary

    The text announces CVE‑2026‑25776 as a code‑injection flaw in Movable Type that could enable arbitrary Perl execution, but contains no PoC, exploit code, patch, or evidence of active exploitation.

    00000126
    57.1K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【Movable Typeにおける複数の脆弱性】 JVNは、Movable TypeにRCE相当のコードインジェクション(CVE-2026-25776、CVSS v3 9.8)とSQLインジェクション(CVE-2026-33088、CVSS v3 7.3)があると公表しました。影響範囲が広く、サポート中の版だけでなくEOL済みの旧版にも及びます。 日本では企業サイト、団体サイト、制作会社管理のWebにMovable Typeが残りやすく、しかも“中の人が版数を把握していない”ケースが少なくありません。そのため、この脆弱性は単なるCMS更新ではなく、公開資産台帳の不備そのものを突いてくる可能性があります。 想定されるのは、公開Web経由の初期侵入、改ざん、DB操作、管理権限奪取、そこから先の横展開です。影響が長寿命の旧版に広がるので、保守契約が切れているサイトほど危険度が上がります。 日本側でまず見るべきは、Movable Typeの存在有無、版数、Data APIの有効化、保守委託先、そしてWAFやアクセスログの異常です。 #MovableType #JVN #CVE202625776 #CVE202633088 #脆弱性対策 https://jvn.jp/jp/JVN66473735/

    Post summary

    The JVN report reveals two high‑severity vulnerabilities in Movable Type (RCE and SQLi), affecting current and legacy versions, with no patch or PoC referenced and no evidence of active exploitation.

    00000243
    3.5K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-2942 | CVSS 9.8 🔴 CVE-2026-25776 | CVSS 9.3 🔴 CVE-2025-14815 | CVSS 9.3 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three high‑scoring CVEs with a link to a vulnerabilities page, but provides no further exploitation, patch, or detailed technical information.

    00000317
    5.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25776: CRITICAL] Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.#cve,CVE-2026-25776,#cybersecurity https://cvefind.com/CVE-2026-25776

    Post summary

    The text announces a critical code injection flaw in Movable Type that could enable arbitrary Perl script execution, with no PoC, exploit, or patch provided.

    00000101
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25776: Six Apart Ltd. (CVSS: 9.8)... Arbitrary Perl execution via code injection in Movable Type CMS—9.8 CVSS with zero auth required means instant webshell... https://zerodaysignal.com/vulnerability/CVE-2026-25776 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-25776, a high‑severity zero‑auth code injection vulnerability in Movable Type CMS that permits arbitrary Perl execution and webshell creation, but offers no patch, exploit code or evidence of active exploitation.

    00000103
    204 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Movable Type — Code Injection (CVE-2026-25776) and SQL Injection (CVE-2026-33088) 📅 **Timeline:** Disclosure: 2026-04-08 🆔 **CVE-2026-25776** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: Not Available% 🆔 **CVE-2026-33088** | 📊 CVSS: 5.3 (Medium 🟡) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Movable Type/Advanced/Premium: 9.1.0 and earlier, 9.0.6 and earlier, 8.8.2 and earlier, 8.0.9 and earlier, End-of-support releases (MT 5–7, MT8.4.x, Premium 1.x) 🔧 **Fixed Versions:** Movable Type 9.1.1 (cloud), 9.0.7, 8.8.3, 8.0.10, Movable Type Premium / MT8 base: 9.1.1 / 2.15 🫨 **Attack Vectors:** - Network (remote) - Unauthenticated attacker - Exposed Data API endpoints - Listing framework (administrative endpoints) 📝 **Summary:** CVE-2026-25776 is a critical code-injection vulnerability allowing unauthenticated remote execution of arbitrary Perl code via the listing-framework or Data API, enabling full system compromise. CVE-2026-33088 is a SQL injection vulnerability allowing unauthenticated SQL execution leading to data disclosure/modification; both stem from insufficient input validation in exposed admin/API components. 📈 **Impact Scope:** Unauthenticated remote RCE (CVE-2026-25776) and unauthenticated SQL execution/data compromise (CVE-2026-33088). Potential for full system compromise depending on deployment, privileges, and exposed interfaces. 🛡️ **Recommended Actions:** - Apply vendor patches immediately to affected installations (see fixed versions). - If patching is not possible, disable or restrict Data API and listing-framework endpoints and remove public exposure. 🪢 **Related Resources:** - https://www.sixapart.jp/movabletype/news/2026/04/08-1100.html - https://jvn.jp/jp/JVN66473735/ 🏷 **Tags:** #Cybersecurity #MovableType #RCE

    Post summary

    The post announces two new vulnerabilities in Movable Type, provides technical details and CVSS scores, and advises prompt patching and mitigation measures.

    0000057
    276 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appsixapartmovable_type---
Appsixapartmovable_type---
Appsixapartmovable_type9.0.5--
Appsixapartmovable_type9.0.6--
Appsixapartmovable_type9.1.0--
Appsixapartmovable_type9.1.0--

Explore more