Skip to content
Ghost CMS flaw abused to push ClickFix attacks on hundreds of sites

Ghost CMS flaw abused to push ClickFix attacks on hundreds of sites

Securityaffairs.Co Pierluigi Paganini May 25, 2026

Attackers are exploiting the patched Ghost CMS flaw CVE-2026-26980, compromising over 700 unpatched sites, including universities. Threat actors are actively exploiting a security flaw, tracked as CVE-2026-26980, in Ghost CMS that was fixed months ago in real attacks against unpatched websites. According to Qianxin, the campaign has already affected more than 700 sites, including well-known organizations and […]

Extracted Entities

Attack Types (1)

Malware (1)

Platforms (1)