Ghost SQLi Turns Sites Into Trusted Malware Launchpads

Ghost CMS is not just leaking data here. A SQL injection flaw can hand attackers admin API keys, and that turns a single web app bug into persistent control over articles, themes, and page content. Cleaning up the SQLi path alone can leave the site still able to deliver malicious JavaScript from trusted pages. XLab says CVE-2026-26980 is being exploited across 700+ domains, including university portals, AI/SaaS firms, media outlets, fintech sites, security sites, and personal blogs. The flaw affects Ghost 3.24.0 through 6.19.0, and the fix is Ghost 6.19.1, released Feb. 19. Researchers also saw malicious code planted on high-profile sites such as Harvard, Oxford, Auburn University, and DuckDuckGo. The forward risk is persistence. Exposed admin API keys let attackers keep modifying content even after the database flaw is patched, so compromised Ghost sites can remain trusted delivery points for ClickFix and other malware lures.

Part of the PlainSec briefing for 2026-05-26

Sources