Hackers Exploit Ghost CMS CVE-2026-26980 to Poison 700 Websites With ClickFix Malware
ID: 4641659d-8751-5031-aac4-cbe11cb855d6
STIX ID: report--4641659d-8751-5031-aac4-cbe11cb855d6
Feed Name: cybersecurityNews.com
**Executive summary:** A high‑risk unauthenticated SQL injection in Ghost CMS (CVE-2026-26980) was weaponized in the wild to steal Admin API keys and poison over 700 websites (including universities) with malicious JavaScript that cloaks traffic, lures users into executing commands via a fake Cloudflare verification page, and ultimately installs a data‑stealing Trojan (ClickFix/UtilifySetup); researchers provide IoCs and recommend immediate patching, credential rotation, log auditing, and content scans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
