news.mlab.sh
Back to the feed
ransomware

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

Critical
Image: The Hacker News
Summary

A critical vulnerability (CVE-2026-26980) in Ghost CMS is being exploited to hijack over 700 websites, primarily through ClickFix attacks. Threat actors are leveraging this SQL injection flaw to steal admin API keys and inject malicious JavaScript, leading to fake CAPTCHA attacks and ultimately, the deployment of malware. The campaign, detected in May 2026, has impacted a diverse range of sectors including SaaS, blockchain, and media.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.