vulnerability
Ghost CMS Vulnerability Exploited to Hack Over 700 Websites
High
Summary
A previously disclosed SQL injection vulnerability (CVE-2026-26980) in the Ghost CMS has been actively exploited by multiple threat actors, leading to the compromise of over 700 websites. The attackers leveraged this vulnerability to steal sensitive data, including authentication tokens and website content, and subsequently altered published content. This incident highlights the ongoing risk posed by unpatched software and the importance of timely security updates.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data