Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
A widespread campaign is using Ghost CMS's serious SQL injection vulnerability (CVE-2026-26980) to insert malicious JavaScript code that initiates ClickFix attack flows.
XLab threat intelligence analysts at the Chinese cybersecurity firm Qianxin found the campaign and verified its impact on over 700 domains, including media sources, fintech companies, university portals, AI/SaaS enterprises, security sites, and individual blogs.
The researchers claim that malicious code was inserted by threat actors on the websites of DuckDuckGo, Harvard University, Oxford University, and Auburn University.
Ghost 3.24.0 through 6.19.0 are affected by CVE-2026-26980, which let unauthenticated attackers to read any data from the website database, including the admin API keys.
This key can be use...


