logo

Hackers Exploit Ghost CMS CVE-2026-26980 to Poison 700 Websites With ClickFix Malware

ID: 4641659d-8751-5031-aac4-cbe11cb855d6

STIX ID: report--4641659d-8751-5031-aac4-cbe11cb855d6

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Tushar Subhra Dutta

...
...

**Executive summary:** A high‑risk unauthenticated SQL injection in Ghost CMS (CVE-2026-26980) was weaponized in the wild to steal Admin API keys and poison over 700 websites (including universities) with malicious JavaScript that cloaks traffic, lures users into executing commands via a fake Cloudflare verification page, and ultimately installs a data‑stealing Trojan (ClickFix/UtilifySetup); researchers provide IoCs and recommend immediate patching, credential rotation, log auditing, and content scans.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.