logo

Ghost CMS Vulnerability Exploited to Infect 700 Sites With ClickFix Malware

ID: 0e53d07d-c17b-5d04-b568-a26e2e3173a6

STIX ID: report--0e53d07d-c17b-5d04-b568-a26e2e3173a6

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Mayura Kathir

...
...

Researchers observed active exploitation of a critical Ghost CMS SQL injection (CVE-2026-26980) that allows attackers to extract Admin API keys, modify site content at scale, and inject JavaScript loaders that chain into fingerprinting, social-engineered CAPTCHA prompts, and delivery of ClickFix-style malware (including data-stealing variants) across 700+ domains spanning academia, media, and SaaS. The campaign uses automated reinfection, infrastructure rotation, and legitimate utilities (e.g., rundll32) to execute payloads, persistent backdoors, and C2 communications; immediate patching, API key rotation, and content/log inspections are strongly advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.