logo

Ghost CMS flaw abused to push ClickFix attacks on hundreds of sites

ID: 86207856-e7ca-53e9-b851-83ca811a70af

STIX ID: report--86207856-e7ca-53e9-b851-83ca811a70af

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-05-25

Date Updated: 2026-05-26

Author: Pierluigi Paganini

...
...

Attackers are actively exploiting a patched SQL injection in Ghost CMS (CVE-2026-26980) to extract Admin API keys and compromise over 700 unpatched sites, including universities; injected JavaScript redirected visitors to a fake CAPTCHA 'ClickFix' flow that social-engineered users into running commands which delivered malware. The campaign is highly automated (bulk scanning, automatic key extraction, bulk injection, dynamic C2), involves at least two competing groups, and includes IoCs—site owners are advised to patch Ghost, rotate credentials, remove injected scripts from the database, and review logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.