Threat actors are injecting malicious JavaScript code to support ClickFix assaults by taking advantage of a recently revealed critical security vulnerability in Ghost CMS.
The activity involves exploiting CVE-2026-26980 (CVSS score: 9.4), a SQL injection vulnerability in Ghost’s Content API that might enable an unauthenticated attacker to read any data from the database, according to QiAnXin XLab. Version 6.19.1 fixed the security vulnerability in February 2026. Anthropic used Claude to find the vulnerability.
The vulnerability is serious since it gives an attacker unauthorized access to a site’s admin API key, enabling them to inject malicious code and contaminate the site. Articles published on the content management system can be directly modified by using the admin API key to access the admin API.
The threat actor “obtained the target site’s Admin API Key without authorization, and then used the Ghost Admin API to tamper with articles in bulk” by taking advantage of the security hole read more about Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
