A large-scale campaign is currently exploiting the critical SQL injection vulnerability CVE-2026-26980 in Ghost CMS to facilitate malicious JavaScript injection and subsequent ClickFix execution flows. Analysis confirms the compromise of over 700 domains across multiple verticals, including higher education portals, enterprise SaaS/AI platforms, financial technology firms, and cybersecurity outlets.
Verified compromises include the public-facing infrastructure of Harvard University, Oxford University, Auburn University, and DuckDuckGo.
The critical security flaw, CVE-2026-26980, affects Ghost CMS deployments spanning versions 3.24.0 through 6.19.0. This vulnerability permits unauthenticated actors to execute arbitrary data exfiltration, facilitating the theft of administrative API keys.
The attack chain leverages the API keys to inject persistent malicious JavaScript into CMS articles. This script renders a fraudulent Cloudflare verification interface via an iframe, instructing victims to execute specific commands within the Windows Command Prompt, XLab researchers at Qianxin said in a recent report.
“ From the current infection situation, the attacker only needs to move the Cloaking domain out of Cloudflare's service, and the attack chain can resume normal operation, with the infected domains immediately becoming accomplices to ClickFix attacks ,” the researchers said.
Through this vector, XLab has observed threat actors delivering multiple sophisticated payloads, including DLL loaders, JavaScript droppers, and the Electron-based malware variant UtilifySetup.exe.
Despite the release of a formal patch in version 6.19.1 on February 19, a significant number of deployments remain unpatched and vulnerable to exploitation . The researchers said they have contacted impacted sites to notify them of the poisoning.
To secure systems against this campaign, XLabs recommends:
In March, ReliaQuest reports outlined a novel DeepLoad malware campaign that uses the ClickFix delivery method, with the payload likely relying on advanced AI-generated evasion, and that ClickFix lures hosted on compromised legitimate websites by the LeakNet ransomware group .
In other recent news, a report found that Google API keys remain usable for up to 23 minutes after deletion.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
