Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
Summary
Threat actors are actively exploiting a critical SQL injection vulnerability, CVE-2026-26980, in Ghost CMS to inject malicious JavaScript. This exploit has already impacted over 700 websites, rerouting them to perform ClickFix attacks.
IFF Assessment
FOE
The exploitation of a critical vulnerability that allows for arbitrary data reading and code injection represents a significant threat to websites and their users.
Severity
9.4
Critical
Defender Context
This incident highlights the importance of promptly patching Ghost CMS, especially critical vulnerabilities like SQL injection flaws. Defenders should monitor their Ghost installations for signs of unauthorized JavaScript injection and suspicious network activity, as similar attacks targeting other content management systems may emerge.