A significant vulnerability (CVE-2026-26980) in the Ghost CMS was exploited, leading to the hijacking of over 700 websites for click-fraud attacks. Security experts emphasize the urgency of addressing this issue and implementing necessary patches to prevent further exploits. The incident highlights the risks associated with web security flaws and the necessity for proactive measures in cybersecurity.
CVE-2026-26980 flaw hijacks 700+ Ghost sites for click fraud
CyberSIXT Evidence Panel
Source marked as original reporting
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Ghost CMS mass hack via CVE-2026-26980 fuels ClickFix attack wave
securityaffairs.com
-
Hackers Hijack 700+ Sites via Ghost CMS SQLi Flaw CVE-2026-26980
malwarebytes.com
-
Ghost CMS SQL flaw lets attackers hijack 700+ sites, steal keys
securityaffairs.com
-
Ghost CMS CVE-2026-26980 SQLi Triggers Attack on 700 Sites
securityweek.com
-
CVE-2026-26980 flaw hijacks 700+ Ghost sites for click fraud
thehackernews.com