Mmastodon TechnologyCybersecurity first seen 10 h ago, last 10 h ago, peak #11
Critical code injection flaw hits Movable Type Cloud Edition
Original: CVE-2026-96408 (CRITICAL): Movable Type Cloud Edition (v2.0 – 9.2.1) hit by code injection in upgrade script — unauthent
A critical vulnerability, CVE-2026-96408, has been disclosed in Movable Type Cloud Edition versions 2.0 through 9.2.1. The flaw is a code injection in the upgrade script, allowing unauthenticated attackers to execute arbitrary Perl and SQL code. No patch is available yet, and administrators are being urged to restrict access to the upgrade script as an interim mitigation while a fix is awaited.
Why now: A newly disclosed critical, unauthenticated remote code execution vulnerability with no patch available is an urgent concern for administrators running affected versions.
Movable TypeCVE-2026-96408Offseq
Evidence
- CVE-2026-96408 (CRITICAL): Movable Type Cloud Edition (v2.0 – 9.2.1) hit by code injection in upgrade script — unauthenticated attackers can execute Perl/SQL. No patch yet; restrict script access. https:// radar.offseq.com/threat/cve-20… · offseq@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1364613