CVE-2026-26980, a vulnerability patched a few months ago in the Ghost CMS, has been exploited to hack hundreds of websites

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.

Ghost CMS flaw CVE-2026-26980 enabled attacks on 700+ sites, injecting ClickFix malware through fake CAPTCHA pages.

CVE-2026-26980, a vulnerability patched a few months ago in the Ghost CMS, has been exploited to hack hundreds of websites