CVE-2026-26980
CVSS 9.4 CRITICAL: ghost is a Node.js content management system. EPSS 70% (99th percentile).
Vulnerabilities · 112 days ago
Ghost CMS is not just leaking data here. A SQL injection flaw can hand attackers admin API keys, and that turns a single web app bug into persistent control over articles, themes, and page content. Cleaning up the SQLi path alone can leave the site still able to deliver malicious JavaScript from trusted pages.
XLab says CVE-2026-26980 is being exploited across 700+ domains, including university portals, AI/SaaS firms, media outlets, fintech sites, security sites, and personal blogs. The flaw affects Ghost 3.24.0 through 6.19.0, and the fix is Ghost 6.19.1, released Feb. 19. Researchers also saw malicious code planted on high-profile sites such as Harvard, Oxford, Auburn University, and DuckDuckGo.
The forward risk is persistence. Exposed admin API keys let attackers keep modifying content even after the database flaw is patched, so compromised Ghost sites can remain trusted delivery points for ClickFix and other malware lures.
CVSS 9.4 CRITICAL: ghost is a Node.js content management system. EPSS 70% (99th percentile).
3 sources covering this story
Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
Ghost CMS flaw CVE-2026-26980 enabled attacks on 700+ sites, injecting ClickFix malware through fake CAPTCHA pages.
Ghost CMS Vulnerability Exploited to Hack Over 700 Websites
Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack.
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.
Part of the PlainSec briefing for 2026-05-26