A critical SQL injection vulnerability in Ghost CMS is being actively exploited to deploy malicious JavaScript in a widespread ClickFix campaign. The flaw, tracked as CVE-2026-26980, allows attackers to inject code that triggers fake tech support scams.
Security researchers have identified a large-scale attack campaign leveraging CVE-2026-26980, a critical SQL injection vulnerability in Ghost CMS. The exploit chain injects malicious JavaScript that initiates ClickFix attack flows—social engineering schemes designed to trick users into believing their devices are compromised.
The vulnerability allows unauthenticated attackers to execute arbitrary SQL queries against affected Ghost instances. By injecting crafted payloads, threat actors compromise websites and insert malicious code that executes in visitors' browsers.
Once injected, the JavaScript triggers fake security warnings claiming the user's system contains malware or viruses. These alerts prompt victims to call a fake support number or download malicious software, leading to credential theft, financial loss, or system compromise.
Ghost CMS, a popular open-source platform used for blogging and content management, has released patches addressing the vulnerability. The development team recommends immediate updates to all affected instances.
Attack Flow:
- Attacker exploits SQL injection in vulnerable Ghost installation
- Malicious JavaScript inserted into site content
- Victim visits compromised website
- Fake security alert displays
- User contacts fake support or downloads malware
Mitigation Steps:
Affected Ghost users should upgrade to the patched version immediately. Security teams should audit access logs for SQL injection attempts and review injected content across their instances. Website visitors encountering suspicious security warnings should close the browser tab and run legitimate antivirus scans.
The campaign demonstrates the continued threat posed by unpatched CMS vulnerabilities and highlights the effectiveness of combining technical exploits with social engineering tactics. Organizations running Ghost should prioritize security updates as part of standard maintenance protocols.
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin exposes WordPress sites to remote code execution and complete takeover by unauthenticated attackers.
An identity theft search site claimed to possess over 150 million driver's license photos stolen from a major ID verification service. The crime site has since been shut down.
Iran-linked hackers have compromised approximately 100 American water utilities in a sustained campaign targeting critical infrastructure. The EPA is allocating $11 million in funding to strengthen cybersecurity defenses across water systems.
Attackers exploited BGP routing vulnerabilities to redirect Virtualizor VPS management software update requests to malicious servers. The compromise affected users attempting to download legitimate updates for the widely-used hosting control panel.