CVE-2026-25776: Sixapart Movable Type

Critical severity, CVSS 9.3. EPSS: 1% chance of exploitation in the next 30 days.

Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.

Affected products

  • Sixapart Movable Type: up to and including 2.14; version 9.0.5 only; version 9.0.6 only; version 9.1.0 only; from 8.0.2, before 8.0.10 (fixed in 8.0.10); from 8.8.0, before 8.8.3 (fixed in 8.8.3); …

Published 2026-04-08. Last modified 2026-07-25.