News

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

  • Bill Toulas--BleepingComputer
  • published date: 2026-05-24 14:12:32 UTC

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. [...]

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. The campaign was di… [+2934 chars]