← Vulnerability feed

Vulnerability record · CVE-2021-20837 · published 26 October 2021

CVE-2021-20837: Movable Type XMLRPC API OS command injection

SSixapart · Movable Type

Movable Type 7, 6, Advanced and Premium editions (and all versions 4.0 or later, including EOL releases) contain an OS command injection flaw reachable through unspecified vectors, with public reporting pointing at the XMLRPC API. Successful exploitation lets a remote, unauthenticated attacker run arbitrary operating system commands on the server, which is severe for a widely deployed publishing platform.

9.8 CVSS 3.1 Critical EPSS 88% · top 0.2% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 7.5
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.46 and earlier, and Movable Type Premium Advanced 1.46 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and very high EPSS plus public exploit references make this an urgent patch target.

What it is

Movable Type 7, 6, Advanced and Premium editions (and all versions 4.0 or later, including EOL releases) contain an OS command injection flaw reachable through unspecified vectors, with public reporting pointing at the XMLRPC API. Successful exploitation lets a remote, unauthenticated attacker run arbitrary operating system commands on the server, which is severe for a widely deployed publishing platform.

Impact

An attacker gains arbitrary OS command execution on the host running Movable Type, enabling full compromise of the application and its data, and potentially the underlying server.

Attack surface

The CVSS vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), and public exploit write-ups reference the XMLRPC API, so the vulnerable endpoint is directly reachable over HTTP. No authentication is required per the vector.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.88144, 99.76th percentile) and public exploit references exist on Packet Storm, indicating active interest and readily available exploit material.

What to do

  • Upgrade to the fixed Movable Type releases referenced in the vendor advisory (MT 7.8.2 / 6.8.3 and corresponding Advanced/Premium builds).
  • If immediate patching is not possible, restrict or block access to the XMLRPC API endpoint at the web server or WAF.
  • Retire or isolate unsupported/EOL Movable Type versions, which the advisory states remain affected.
  • Run the Movable Type service under a low-privilege account with no unnecessary OS permissions.
  • Monitor vendor and JVN advisories for updated guidance.

Detection

  • Inspect web server and application logs for POST requests to XMLRPC endpoints with suspicious or shell-like payload content.
  • Alert on unexpected child processes spawned by the web server or application user (e.g., shell, curl, wget).
  • Monitor for outbound network connections originating from the Movable Type host to unfamiliar destinations.
  • Review file integrity on the Movable Type installation and web root for newly written files or modified scripts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20837 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-0752Sixapart movable type vulnerabilityUnspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vectors, possibly related to the p…EPSS 1.4%9.8CVE-2022-38078Sixapart movable type code injection vulnerabilityMovable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to …EPSS 2.1%9.8CVE-2016-5742Sixapart movable type sql injection vulnerabilitySQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open S…EPSS 1.6%9.3CVE-2026-25776Sixapart movable type code injection vulnerabilityMovable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.EPSS 0.73%8.8CVE-2020-5576Sixapart movable type cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Adva…EPSS 0.84%8.8CVE-2020-5577Sixapart movable type unrestricted file upload vulnerabilityMovable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Adv…EPSS 1.7%7.5CVE-2013-2184Sixapart movable type vulnerabilityMovable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_…EPSS 3.6%7.5CVE-2015-1592Movable Type improper Storable::thaw use allows local Perl file inclusion and code executionMovable Type Pro, Open Source, and Advanced before 5.2.12 and Pro/Advanced 6.0.x before 6.0.7 do not properly use the Perl Storable::thaw function. T…EPSS 75%analysed

Source: NIST National Vulnerability Database (record CVE-2021-20837), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.