CVE-2026-25776: Code Injection
Published Apr 8, 2026
·Updated
Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.
Affected Software
9 affected components
Six Apart Movable Type
Sixapart Movable Type<=2.14
Sixapart Movable Type=9.0.5
Sixapart Movable Type=9.0.6
Sixapart Movable Type=9.1.0
Sixapart Movable Type>=8.0.2<8.0.10
Sixapart Movable Type>=8.8.0<8.8.3
Sixapart Movable Type>=9.0.1<9.0.7
Sixapart Movable Type=9.1.0
Event History
Apr 8, 2026
CVE Published
via MITRE·08:52 AM
Data Sourced
via MITRE·08:52 AM
DescriptionSeverity
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-25776?
CVE-2026-25776 is rated as critical with a severity score of 9.3.
2
What does CVE-2026-25776 affect?
CVE-2026-25776 affects the Movable Type software provided by Six Apart Ltd.
3
What type of vulnerability is CVE-2026-25776?
CVE-2026-25776 is a code injection vulnerability that may allow arbitrary Perl script execution.
4
How do I fix CVE-2026-25776?
To fix CVE-2026-25776, update to the latest version of Movable Type as recommended by Six Apart.
5
What are the potential risks of CVE-2026-25776?
The potential risks of CVE-2026-25776 include unauthorized access and execution of malicious scripts on the affected system.