Ghost CMS Bug Hijacked to Target Hundreds of Websites with ClickFix Attack – Here’s How to Stay Safe


  • Researchers warn that CVE-2026-26980, a critical SQL injection flaw in Ghost CMS (score 9.4), is being exploited in a large ClickFix campaign
  • Over 700 domains, including Harvard, Oxford, DuckDuckGo, and major AI/SaaS companies, were compromised to deliver malware via DLL loaders, JS droppers, and electron-based payloads
  • Administrators should immediately upgrade to Ghost 6.19.1 or later and monitor 30-day admin API logs to detect potential compromise

A Critical Severity vulnerability that was reportedly patched three months ago is being exploited in a massive ClickFix campaign, researchers have claimed.

In mid-February 2026, a critical SQL injection vulnerability was found in Ghost CMS, a popular open source Content Management System (CMS) currently used by more than 57,000 websites, including 404 Media, the Canadian government, and Duolingo.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top