CRITICAL
9.4 CVE-2026-96408 Published 7 Oct 2026
Movable Type Upgrade Script Code Injection Vulnerability
Worried this affects your website?
A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.
This code injection flaw could be exploited without authentication, potentially leading to full compromise of the CMS installation.
Reference: CVE-2026-96408 on NVD
← Back to Security News