CVE-2026-96408

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-07: 110-07
Referenced assets1 URL
By indicator
Full discourse1 post
  • Autumn Good@autumn_good_35

    🚨🚨🚨 ・システム上で任意のPerlコードやSQLクエリが実行される(CVE-2026-96408) ・システム上でSQLクエリが実行される(CVE-2026-103668) 2026/10/07 JVN#91153973: Movable Typeにおける複数の脆弱性 https://jvn.jp/jp/JVN91153973/index.html

    00002384
    7.3K followersView on X

Explore more