CVE-2026-26980 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
13
occurrences
First Seen
May 24, 2026
Last Seen
May 26, 2026

CVE-2026-26980 is a vulnerability tracked across 3 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed May 24, 2026; most recent activity May 26, 2026.

Related Threat Clusters

  • Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign

    A critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS is being actively exploited in a large-scale cyberattack affecting over 700 websites, including those of Harvard University, Oxford University, Auburn…

    17 articles · Updated May 25, 2026
  • Critical SQL Injection Vulnerability in Ghost CMS Exploited

    CVE-2026-26980 is a SQL Injection vulnerability affecting Ghost, a Node.js content management system, allowing unauthenticated attackers to perform arbitrary database reads. The flaw exists in the Content API's slug…

    2 articles · Updated May 24, 2026
  • NightSpire Ransomware Exploits RDP for Widespread Attacks

    NightSpire ransomware, identified in early 2025, has rapidly become a significant threat, employing double-extortion tactics. It targets various sectors, including hospitals and government offices, by exploiting Remote…

    3 articles · Updated May 26, 2026

Recent Intelligence Reports

  • Hackers Exploit Ghost CMS CVE-2026 — Cybersecuritynews · May 26, 2026
  • SentinelOne Advisory — www.sentinelone.com · May 26, 2026
  • NightSpire Ransomware Abuses RDP for Stealthy Persistence — Gbhackers · May 26, 2026
  • Critical Ghost CMS Vulnerability Exploited to Hack 700+ Websites — Thecyberexpress · May 26, 2026
  • Ghost CMS Vulnerability Exploited to Infect 700 Sites With ClickFix Malware — Gbhackers · May 26, 2026
  • Ghost CMS CVE-2026-26980 Mass Attack Hijacks 700+ Sites for ClickFix Malware Campaigns — Rescana · May 26, 2026
  • Ghost CMS flaw abused to push ClickFix attacks on hundreds of sites — Securityaffairs.Co · May 25, 2026
  • Ghost CMS SQL Injection Hits 700 Sites: Harvard, DuckDuckGo Serve Fake Cloudflare Malware — Techtimes · May 25, 2026

CVSS v3.1 Breakdown