logo

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

ID: 412c8b57-6851-5eb8-bc10-6a9d7327954a

STIX ID: report--412c8b57-6851-5eb8-bc10-6a9d7327954a

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: [email protected] (The Hacker News)

...
...

Security researchers observed threat actors exploiting a critical SQL injection (CVE-2026-26980, CVSS 9.4) in Ghost CMS to steal Admin API keys and bulk-inject a two-stage JavaScript loader into articles on 700+ sites across universities, blockchain, AI, SaaS, media and fintech. The loader uses a commercial cloaking service to fingerprint visitors and serve a fake CAPTCHA that tricks victims into running a Base64 command, which downloads archives that execute PowerShell/JavaScript to deliver DLLs or installers (including a signed PuTTY binary and a modified Electron app) that maintain persistence and poll a command server; operators can swap payloads remotely. Users are advised to upgrade Ghost, rotate credentials, clean sites, audit logs, and notify potentially impacted visitors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.