Skip to content

Hackers Exploit Ghost CMS CVE-2026

Cybersecuritynews Tushar Subhra Dutta May 26, 2026

A critical SQL injection flaw in Ghost CMS has been weaponized by at least two threat actor groups to silently poison over 700 websites with ClickFix malware, putting unsuspecting visitors at serious risk. The vulnerability, tracked as CVE-2026-26980, was publicly disclosed as early as February 19, 2026. Despite this, many Ghost CMS administrators failed to […]

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Malware (1)

Platforms (1)