logo

Ghost CMS Under Siege: How a SQL Injection Turned 700+ Blogs Into Malware Distribution Networks

ID: c5c86453-0848-5895-90a7-13e9abcfb04a

STIX ID: report--c5c86453-0848-5895-90a7-13e9abcfb04a

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Deepak Gupta

...
...

A critical unauthenticated SQL injection (CVE-2026-26980, CVSS 9.4) in Ghost CMS was weaponized in a large-scale campaign that compromised over 700 domains — including university and corporate properties — by stealing Admin API keys and injecting malicious JavaScript that uses a fake Cloudflare prompt (the 'ClickFix' technique) to trick visitors into executing malware; a patch (6.19.1) was available in February 2026 but many self-hosted sites remained unpatched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.