Attackers are actively exploiting CVE-2026-26980, a critical SQL injection flaw in Ghost CMS, to compromise more than 700 unpatched websites and turn them into malware delivery platforms. The vulnerability, patched in Ghost 6.19.1, allows exposure of the Admin API key through the Content API, giving attackers the ability to take over sites and alter published content. Researchers said the campaign has affected organizations across higher education, media, fintech, AI, SaaS, blockchain, and security research, with evidence suggesting the flaw was weaponized almost immediately after disclosure and that at least two separate threat groups have been abusing it, sometimes targeting the same sites.
The intrusions rely on injected malicious JavaScript that redirects visitors into ClickFix social-engineering flows, including fake CAPTCHA or human-verification prompts that instruct users to paste a Base64-encoded command into the Windows Run dialog. The staged infection chain has delivered ZIP, batch, PowerShell, DLL, JavaScript, and Windows executable payloads, with infrastructure including clo4shara[.]xyz/11z77u3.php and web-telegram[.]ug, and cloaking used to evade detection. Defenders are being urged to upgrade Ghost immediately, rotate API credentials, inspect logs for suspicious Admin API activity, remove injected scripts from stored content, and notify visitors who may have been exposed.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Researchers revealed that the injected code functioned as a two-stage loader, retrieving payloads from clo4shara[.]xyz/11z77u3.php and using Adspect cloaking to selectively serve fake CAPTCHA lures. Victims were tricked into executing Base64-encoded commands that led to multi-stage malware delivery and, in some cases, persistence via a modified Grape desktop client communicating with web-telegram[.]ug.
QiAnXin assessed that at least two separate threat groups were conducting the website-poisoning operations, sometimes competing over the same compromised sites. The campaign used dynamic infrastructure changes, flexible payload delivery, and cloaking to evade detection.
Qianxin XLab reported that by May 10, 2026, the Ghost CMS exploitation campaign had already poisoned 156 confirmed domains. The count showed the operation scaling rapidly only days after active exploitation was first detected on May 7.
Threat actors hijacked more than 700 unpatched Ghost CMS sites across sectors including universities, media, fintech, SaaS, AI, blockchain, and security research. They injected malicious JavaScript into trusted pages to turn them into delivery points for ClickFix-style social engineering.
QiAnXin observed active exploitation of CVE-2026-26980 beginning by early May 2026, with one report specifying activity since at least May 7. Attackers used automated scanning and key extraction to identify and compromise unpatched Ghost CMS instances.
Malicious code tied to the campaign carried a compilation date matching the day Ghost announced the fix, indicating attackers quickly developed exploit tooling after public disclosure. This suggests near-immediate weaponization of the patched vulnerability.
Ghost fixed the critical SQL injection vulnerability CVE-2026-26980 in February 2026 with the release of version 6.19.1. The flaw in the Content API could expose the Admin API key and enable site takeover.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcethecyberexpress.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.