Not a developer? Go to MovableType.com

News

Movable Type 9.3.0 / 9.0.10 / 8.8.6 / 8.0.13 Released

By Daiji Hirata
Posted October 7, 2026, in MT Newsbox.

Critical security issues were found and fixed in the Listing Framework of Movable Type.

For those of you who use Movable Type 4.0 and later, Six Apart strongly recommends that you upgrade to the latest version or execute one of the following workarounds immediately.

Detail of the Issues

  • Remote Code Execution and SQL Injection via Upgrade Script: A vulnerability was found in the upgrade script (mt-upgrade.cgi) that could allow remote code execution (RCE) or arbitrary SQL commands to be executed (MTC-31703/CVE-2026-96408).
  • SQL Injection via Search Script: A vulnerability was found in the site search (mt-search.cgi and mt-ftsearch.cgi) that could allow arbitrary SQL execution, potentially exposing unpublished data (MTC-31457/CVE-2026-103668).

Workarounds for those who cannot upgrade to the latest version

If you cannot upgrade immediately, please apply the following workarounds according to your operating environment (CGI or PSGI) to reduce or avoid the impact of these vulnerabilities.

For CGI Environments (All Versions)

  • Block access to or delete mt-upgrade.cgi, mt-search.cgi, and mt-ftsearch.cgi: Restrict web access to these script files so they cannot be executed from outside, or remove the files from your server.

For PSGI Environments (Movable Type 6.0 and later)

  • Movable Type 6.2 and later: Configure the RestrictedPSGIApp environment variable in your mt-config.cgi as follows(e.g. RestrictedPSGIApp upgrade, RestrictedPSGIApp new_search, RestrictedPSGIApp ft_search).
  • Movable Type 6.0 and 6.1: Set the UpgradeScript and SearchScript environment variables to sufficiently long, unpredictable string values in your mt-config.cgi.

Note: These are temporary mitigation steps. Since these vulnerabilities affect core framework components, upgrading to the latest version is the only way to fully resolve the issues.

RELEASED VERSIONS

  • Movable Type 9.3.0
  • Movable Type Advanced 9.3.0
  • Movable Type AMI (via AWS Marketplace) 9.3.0
  • Movable Type 9.0.10
  • Movable Type Advanced 9.0.10
  • Movable Type AMI (via AWS Marketplace) 9.0.10
  • Movable Type 8.8.6
  • Movable Type Advanced 8.8.6
  • Movable Type AMI (via AWS Marketplace) 8.8.6
  • Movable Type 8.0.13
  • Movable Type Advanced 8.0.13
  • Movable Type AMI (via AWS Marketplace) 8.0.13

RELEASE NOTES

Please review the Movable Type release notes to see everything that was added and improved since the version you are currently using.

End of Maintenance

Please note the End of Maintenance (EOM) and End of Life (EOL) dates for the following versions:

  • Movable Type 8.0.x: Reached EOM on November 6th, 2024. Security support (EOL) will be provided until November 5th, 2026.

For more details on product support periods, please refer to the Movable Type Lifecycle Policy.

HOW TO GET MOVABLE TYPE

If you have an existing Movable Type license, you can download the latest Movable Type from our download portal using your Six Apart ID. To purchase a new license or an upgrade, please visit MovableType.com for more information, or feel free to contact us if you have any questions.

Back