LIVE NEWS
  • Apple Will Reportedly Add Bill-Splitting Feature to iOS 27
  • Opinion | Putin Has No Good Way Out of His War
  • Flowise’s MCP implementation can run ghost commands
  • DOE Restarts Home Efficiency Rebates, and Electrification Is the Biggest Loser
  • Albania prosecutors probe Jared Kushner-linked resort amid violent protests
  • Clinical Workflow Automation: Where AI Is Making Real Inroads
  • AMD Radeon RX 9070 GRE review: A cheaper GPU for a wildly expensive era
  • US court upholds injunction against Trump policy banning transgender troops | Donald Trump News
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
Cybersecurity

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

primereportsBy primereportsMay 24, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
Share
Facebook Twitter LinkedIn Pinterest Email


Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.

The campaign was discovered by XLab threat intelligence researchers at Chinese cybersecurity company Qianxin, who confirmed impact on more than 700 domains, including university portals, AI/SaaS companies, media outlets, fintech firms, security sites, and personal blogs.

According to the researchers, threat actors planted malicious code on the websites of Harvard University, Oxford University, Auburn University, and DuckDuckGo.

Compromised sites
Compromised sites
Source: XLab

 

CVE-2026-26980 impacts Ghost 3.24.0 through 6.19.0, and allows unauthenticated attackers to read arbitrary data from the website database, including the admin API keys.

This key gives management access to users, articles, and themes, and can be used to modify article pages.

Although the fix for the issue was released on February 19 in Ghost CMS version 6.19.1, many sites failed to install the security update.

SentinelOne published on February 27 details about CVE-2026-26980 being exploited in attacks and how incidents can be detected. The researchers observed at least two distinct activity clusters targeting vulnerable Ghost sites, sometimes re-infecting the same domains with different scripts after cleanup, or one cleaning the script of the other to inject its own.

Timeline of the attacks
Timeline of the attacks
Source: XLab

Attack chain

The attacks that XLab observed begin by exploiting CVE-2026-26980 to steal the admin API keys, and then use the elevated rights to inject malicious JavaScript into articles.

The JavaScript code is a lightweight loader that fetches second-stage code from the attacker’s infrastructure, which is essentially a cloaking script that fingerprints visitors to determine whether they qualify as targets.

Visitors passing the verification are served a fake Cloudflare prompt loaded via an iframe on top of the article page, which contains the ClickFix lure.

The ClickFix page
The ClickFix page
Source: XLab

The page instructs victims to verify that they are human by pasting a provided command on their Windows command prompt, which drops a payload on their systems.

XLab has observed multiple payloads being used in these attacks, including DLL loaders, JavaScript droppers, and an Electron-based malware sample named UtilifySetup.exe.

Attack phases
Attack phases
Source: XLab

Mitigating the risk

The most important course of action for Ghost CMS website administrators is to upgrade to version 6.19.1 or later and rotate all keys used previously, as they may have been exposed.

XLab provided a list of indicators of compromise (IoCs), including injected scripts, so a thorough review of the websites is needed to locate and remove them.

The researchers recommend that website owners maintain a 30-day record of admin API call logs to enable a reliable retrospective investigation.


article image

Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.

This guide covers the 6 surfaces you actually need to validate.

Download Now

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSundar Pichai Says Booing Graduates Will Live With AI’s Consequences
Next Article Solana Activity Hits Record High Despite SOL’s 33% Q1 Drop
primereports
  • Website

Related Posts

Cybersecurity

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

June 1, 2026
Cybersecurity

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada – Krebs on Security

June 1, 2026
Cybersecurity

As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution

June 1, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Apple Will Reportedly Add Bill-Splitting Feature to iOS 27
  • Opinion | Putin Has No Good Way Out of His War
  • Flowise’s MCP implementation can run ghost commands
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.