CVE-2021-20837 is a remote command execution vulnerability affecting multiple Movable Type product lines, including Movable Type 7 r.5002 and earlier, Movable Type 6.8.2 and earlier, Movable Type Advanced 7 r.5002 and earlier, Movable Type Advanced 6.8.2 and earlier, Movable Type Premium 1.46 and earlier, and Movable Type Premium Advanced 1.46 and earlier. Unsupported Movable Type versions from 4.0 onward are also affected. The flaw allows a remote attacker to execute arbitrary operating system commands via unspecified vectors. Public reporting indicates exploitation began shortly after proof-of-concept code became available, and attacks leveraged web-shell tooling following successful compromise.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Metasploit module (cve-2021-20837.rb) that exploits CVE-2021-20837, a remote command injection vulnerability in the Movable Type XMLRPC API. The exploit works by sending a specially crafted XMLRPC request to the 'mt-xmlrpc.cgi' endpoint, injecting arbitrary system commands encoded in base64. The module is weaponized, supporting customizable command payloads (defaulting to a reverse netcat shell) and is compatible with Metasploit's payload system. The README provides attribution and a reference to a blog post. The main code file is well-structured, with methods for vulnerability checking and exploitation, and uses standard Metasploit conventions. The attack vector is network-based, targeting the HTTP endpoint '/cgi-bin/mt/mt-xmlrpc.cgi'.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Movable Type vulnerability observed being targeted in malicious requests.
A specific vulnerability in the Movable Type CMS (published Oct 2021) that was exploited in attacks targeting Movable Type deployments, with exploitation beginning shortly after public PoC release.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.