Critical SQL Injection Vulnerability in Ghost CMS Exploited to Inject Malicious Scripts Through ClickFix Campaign
284/69 Tuesday, May 26, 2026 Researchers have identified a large-scale attack campaign exploiting the critical SQL Injection vulnerability CVE-2026-26980 in Ghost CMS to inject malicious JavaScript into websites, leading to ClickFix-style attacks. According to threat intelligence researchers from Qianxin XLab, more than 700 affected domains have been identified, including websites belonging to universities, AI/SaaS companies, […]
