The CVE-2026-26980 vulnerability in Ghost CMS is being used by cybercriminals to compromise over 700 sites and perform ClickFix attacks . According to research team QiAnXin XLab , the campaign began on May 7, 2026 , targeting university, blockchain, AI, and fintech websites. The speed of the attack’s spread suggests automated exploitation using sophisticated data scanning and extraction tools.

CVE -2026-26980 is a critical vulnerability SQL injection with a CVSS score of 9.4 affecting the Content API of Ghost CMS in versions 3.24.0 through 6.19.0. The vulnerability allows unauthenticated attackers to read arbitrary data from the database, including Admin API keys, encrypted passwords , and session secrets . The vulnerability was discovered by Anthropic using Claude AI, and the fix was released in February 2026 in version 6.19.1. The fact that the vulnerability was discovered by artificial intelligence highlights the importance of automated security tools in our time.
Attackers exploit the vulnerability to gain unauthorized access to the Admin API keys of targeted websites, which allows them to “poison” the website by injecting malicious code. The admin API key can be used to activate the admin API and can directly modify articles published in the content management system.
See also: TrapDoor: Supply Chain Attack on npm, PyPI and CratesIO
They then use the Ghost Admin API to bulk edit articles by injecting malicious JavaScript into the bottom of the pages. This code acts as a two-stage loader that retrieves the main payload from an external domain (clo4shara[.]xyz/11z77u3.php). This methodology allows attackers to maintain control over multiple compromised websites simultaneously.

Technical details of the Ghost CMS attack
The attack architecture offers cybercriminals flexibility, allowing them to change payloads based on different criteria, while maintaining loader functionality across multiple compromised websites. The PHP script used is powered by Adspect, a commercial cloaking service that collects fingerprinting information from the user’s browser. This service analyzes parameters such as browser type, operating system, IP address, and other characteristics to determine whether the visitor is a real user or an automated security tool.
The cloaking service ensures that only real victims receive the real payload, while security scanners and crawlers only see an innocent web page. The script supports 19 different commands to execute arbitrary JavaScript and facilitate remote control of the victim's browser. These commands include redirects, pop-ups, file downloads , and code execution, creating a complete command-and-control system via the browser.
See also: Megalodon attack on GitHub targeted 5,561 repositories with malicious CI/CD
Victim visitors eventually see a fake CAPTCHA verification page within an iframe HTML element to prove they are human. This leads to a ClickFix attack , in which users are instructed to copy and paste a Base64-encoded command into the Windows Run dialog box . This technique exploits users’ trust in verification processes and tricks them into executing malicious code on their system.
The command acts as a dropper to deliver a ZIP file and extracts a Windows batch script and executes it. The script executes a PowerShell to download a DLL file from a remote domain, launch it using rundll32.exe , and open a fake website for the user as a distraction. In newer iterations of the malware, researchers have observed the DLL with a JavaScript payload, while in some cases the final executable is a PuTTY client with a valid code signing certificate or an Inno Setup installer.

Attack impact
The campaign has compromised more than 700 websites spanning sectors such as academia, blockchain, AI, SaaS, security research, media, and fintech. The fact that legitimate websites have been compromised could further increase the success rate of ClickFix attacks, as users tend to trust well-known and reputable websites. The geographic distribution of the affected websites indicates a global reach, with a particular focus on high-value organizations that handle sensitive information.
See also: LiteSpeed cPanel Plugin: Critical vulnerability actively exploited
Protection and treatment recommendations
Organizations should immediately upgrade their Ghost CMS to version 6.19.1 or later to protect against this vulnerability. Additionally, it is recommended to review database access logs for suspicious read and output patterns, and to scan exposed Ghost instances for modified posts or installed scripts. Deploying Web Application Firewall (WAF) rules that detect SQL injection attempts can provide additional protection . Administrators should also restrict access to the Content API to trusted sources and implement rate limiting to make it more difficult for automated attacks.
QiAnXin XLab reports that at least two different threat groups are believed to be behind the campaign, in some cases implanting malicious code on specific websites within a single day. This speed of re-infection suggests organized and well-equipped groups with automated exploitation tools.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
