Ghost CMS Under Siege: How a SQL Injection Turned 700+ Blogs Into Malware Distribution Networks
ID: c5c86453-0848-5895-90a7-13e9abcfb04a
STIX ID: report--c5c86453-0848-5895-90a7-13e9abcfb04a
Feed Name: Security Boulevard
Threat Score
A critical unauthenticated SQL injection (CVE-2026-26980, CVSS 9.4) in Ghost CMS was weaponized in a large-scale campaign that compromised over 700 domains — including university and corporate properties — by stealing Admin API keys and injecting malicious JavaScript that uses a fake Cloudflare prompt (the 'ClickFix' technique) to trick visitors into executing malware; a patch (6.19.1) was available in February 2026 but many self-hosted sites remained unpatched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
