Ghost CMS flaw exploited to hijack over 700 websites in ClickFix campaign

A SQL injection vulnerability in Ghost CMS has been exploited to compromise more than 700 websites. Hijacked sites are being used to distribute fake Cloudflare malware via ClickFix attacks.

Ghost CMS flaw exploited to hijack over 700 websites in ClickFix campaign

Ghost CMS SQL injection flaw used to hijack 700+ sites

Google News MT reports that attackers have exploited a SQL injection vulnerability in Ghost CMS — tracked as CVE-2026-26980 — to compromise more than 700 websites in a large-scale ClickFix campaign.

The hijacked sites, which include high-profile domains associated with institutions such as Harvard and DuckDuckGo, are being used to serve fake Cloudflare verification pages. Visitors who interact with these pages are tricked into executing malicious commands on their own machines, a technique known as ClickFix.

Security researchers at BleepingComputer, The Hacker News, and SecurityWeek have all confirmed the exploitation. The flaw allows unauthenticated attackers to inject malicious SQL queries into vulnerable Ghost CMS installations, granting them effective control over affected sites.

Ghost CMS is a widely used open-source publishing platform. No patch details were included in the available reporting at the time of publication.

The scale of the campaign — spanning hundreds of compromised domains — points to an automated exploitation operation. Administrators running Ghost CMS installations are advised to monitor official security advisories for guidance on remediation.

Source: Google News MT