<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Hackers Use Ghost CMS Flaw to Infect 700+ Websites With ClickFix Malware

Discover how a critical Ghost CMS flaw (CVE-2026-26980) enabled hackers to infect over 700 sites with malware. Patch and secure your site now.
Content Team

A critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) has been exploited by at least two hacker groups to quietly poison over 700 websites with ClickFix malware. First disclosed February 19, 2026, the flaw lets unauthenticated attackers steal Admin API keys and rewrite article content at scale.

Researchers at Qianxin XLab spotted the campaign on May 7. By May 17, compromised sites included Harvard, Oxford, and Auburn University, spanning blockchain, fintech, and media industries. Visitors saw nothing suspicious — malicious JavaScript hid at the bottom of articles, eventually serving a fake Cloudflare verification page that tricked users into running malware themselves.

Ghost CMS admins should patch immediately, rotate all credentials, and audit access logs.

Source: Cyber Security News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo