Ghost CMS Vulnerability Exploited in Large-Scale ClickFix Campaign Affecting Over 700 Domains
Rapid Read

Ghost CMS Vulnerability Exploited in Large-Scale ClickFix Campaign Affecting Over 700 Domains

What's Happening? A critical SQL injection vulnerability in Ghost CMS, identified as CVE-2026-26980, is being exploited in a large-scale campaign. The attack involves injecting malicious JavaScript code that triggers ClickFix attack flows. Discovered by XLab threat intelligence researchers at Qianxi
Summarized by AI
AI Generated
This may include content generated using AI tools. Glance teams are making active and commercially reasonable efforts to moderate all AI generated content. Glance moderation processes are improving however our processes are carried out on a best-effort basis and may not be exhaustive in nature. Glance encourage our users to consume the content judiciously and rely on their own research for accuracy of facts. Glance maintains that all AI generated content here is for entertainment purposes only.