www.malwarebytes.com 5/26/2026, 11:32:15 AM · external

Hackers Hijack 700+ Sites via Ghost CMS SQLi Flaw CVE-2026-26980

Hackers Hijack 700+ Sites via Ghost CMS SQLi Flaw CVE-2026-26980
CyberSIXT Evidence Panel
Primary Source nvd.nist.gov
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A significant malware campaign, termed ClickFix, has hijacked over 700 education and tech websites by exploiting a SQL injection vulnerability (CVE-2026-26980) in the Ghost Content Management System. Attackers injected malicious JavaScript that prompts users with a fake Cloudflare verification, tricking them into executing harmful commands that install malware.

This vulnerability, impacting Ghost versions 3.24.0 to 6.19.0, allows illicit access to the site's database, compromising admin keys and facilitating further exploitation. Website managers are urged to update to the latest patched version to mitigate threats, while users are advised to practice caution when following webpage instructions and running commands. Preventative measures include using up-to-date anti-malware solutions and being wary of copy-pasting commands from untrusted sources.

View Primary Source Via www.malwarebytes.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline