Hackers Use Ghost CMS Flaw to Infect 700+ Websites With ClickFix Malware
Want more insights like this?
A critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980, CVSS 9.4) has been exploited by at least two hacker groups to quietly poison over 700 websites with ClickFix malware. The flaw sits in Ghost's Content API and lets unauthenticated attackers steal Admin API keys, then rewrite article content at scale.
It was disclosed and patched on February 19, 2026 in Ghost 6.19.1, with versions 3.24.0 through 6.19.0 vulnerable — so the sites hit in May had been exposed for three months. Researchers at Qianxin XLab spotted the campaign on May 7: 156 poisoned domains by May 10, more than 700 by May 17.
Victims span universities, blockchain, AI, fintech and media, including Harvard, Oxford and Auburn. Visitors saw nothing suspicious — malicious JavaScript hid at the bottom of articles, eventually serving a fake Cloudflare verification page that tricked users into running malware themselves.
Ghost CMS admins should patch to 6.19.1 or later and rotate every key and admin password — XLab watched cleaned sites get reinfected where old Admin API keys still worked. Then audit access logs for unusual bulk PUT requests.
Source: Cyber Security News