:
[SECURITY]■ STORY TIMELINE

GHOST CMS FLAW FUELS MASSIVE CLICKFIX ATTACK

A critical SQL injection vulnerability in Ghost CMS is being actively exploited to deploy malicious JavaScript in a widespread ClickFix campaign. The flaw, tracked as CVE-2026-26980, allows attackers to inject code that triggers fake tech support scams.

1 SOURCEFIRST SEEN MAY 24, 02:12 PM► READ THE ARTICLE
Bleeping Computer+0m

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject mali…