<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Hackers Use Ghost CMS Flaw to Infect 700+ Websites With ClickFix Malware

Discover how a critical Ghost CMS flaw (CVE-2026-26980) enabled hackers to infect over 700 sites with malware. Patch and secure your site now.
Content Team

A critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980, CVSS 9.4) has been exploited by at least two hacker groups to quietly poison over 700 websites with ClickFix malware. The flaw sits in Ghost's Content API and lets unauthenticated attackers steal Admin API keys, then rewrite article content at scale.

It was disclosed and patched on February 19, 2026 in Ghost 6.19.1, with versions 3.24.0 through 6.19.0 vulnerable — so the sites hit in May had been exposed for three months. Researchers at Qianxin XLab spotted the campaign on May 7: 156 poisoned domains by May 10, more than 700 by May 17.

Victims span universities, blockchain, AI, fintech and media, including Harvard, Oxford and Auburn. Visitors saw nothing suspicious — malicious JavaScript hid at the bottom of articles, eventually serving a fake Cloudflare verification page that tricked users into running malware themselves.

Ghost CMS admins should patch to 6.19.1 or later and rotate every key and admin password — XLab watched cleaned sites get reinfected where old Admin API keys still worked. Then audit access logs for unusual bulk PUT requests.

Source: Cyber Security News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo