CVE-2026-96408: Six Apart Ltd Movable Type
Critical severity, CVSS 9.3. EPSS: 0.6% chance of exploitation in the next 30 days.
A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.
Affected products
- Six Apart Ltd Movable Type: from 9.0.0, up to and including 9.0.9; from 8.8.0, up to and including 8.8.5; from 8.0.0, up to and including 8.0.12
- Six Apart Ltd Movable Type Cloud Edition: from 9.2.0, up to and including 9.2.1
- Six Apart Ltd Movable Type Premium: from 9.0.0, up to and including 9.0.9; from 2.0, up to and including 2.17
- Six Apart Ltd Movable Type Premium Cloud Edition: from 9.2.0, up to and including 9.2.1
Published 2026-10-07. Last modified 2026-10-07.