CVE-2026-26980: Ghost CMS SQL Injection Actively Exploited to Hijack 700+ Sites for ClickFix Attacks
Technical breakdown of the Ghost CMS SQL injection exploited at scale to inject fake browser update (ClickFix) malware into 700+ websites.
CVE-2026-26980
Severity: CVSS 9.8
Status: ⚠️ Mass In-The-Wild Exploitation (ClickFix Malware)
Target Component: Ghost CMS
CVE-2026-26980 (CVSS 9.4) is an SQL injection vulnerability in Ghost CMS's unauthenticated Content API, patched in version 6.19.1 in February 2026. Attackers began exploiting it at scale on May 7, 2026, and as of May 25, QiAnXin XLab had confirmed more than 700 websites compromised — spanning universities, blockchain companies, SaaS providers, security research firms, media, and fintech.
Vulnerability
The vulnerability lives in Ghost's unauthenticated Content API. By injecting a crafted SQL payload, an unauthenticated attacker can read arbitrary data from the database — including the site's Admin API key. The Admin API key grants full control over the Ghost instance: creating, modifying, and deleting posts and pages.
Attack Chain
- Attacker sends crafted SQL payload to the unauthenticated Content API endpoint.
- Admin API key is extracted from the database response.
- Attacker calls the Ghost Admin API to retrieve all published posts.
- Malicious JavaScript loader (
<script src="...">) is injected at the bottom of every article in bulk via the Admin API. - The loader fetches the main payload from
clo4shara[.]xyz/11z77u3.phpat runtime. - The PHP script (powered by the Adspect cloaking service) fingerprints each visitor, serving real victims a fake CAPTCHA page via an iframe.
- The CAPTCHA page triggers a ClickFix attack: victims are instructed to open the Windows Run dialog and paste a Base64-encoded PowerShell command.
- The command downloads and executes a ZIP archive containing a Windows batch script.
- The batch script downloads a DLL via PowerShell, launches it with
rundll32.exe, and opens a decoy webpage. - Subsequent iterations replaced the DLL with a JavaScript payload that installs a modified Grape desktop client achieving persistence and polling
web-telegram[.]ugevery 30 seconds for C2 commands.
Affected Versions
All Ghost CMS versions prior to 6.19.1. The vulnerability was originally discovered by Anthropic's Claude Mythos AI system.
IOCs
- C2/loader:
clo4shara[.]xyz - C2/persistence:
web-telegram[.]ug - Cloaking: Adspect commercial cloaking service
- Two distinct threat clusters identified by QiAnXin XLab
Detection
Review Ghost access logs for unusual Content API queries with abnormal parameters. Look for bulk PUT /ghost/api/admin/posts/{id}/ requests following API key extraction. Inspect all published articles for injected <script> tags at the bottom of article HTML.
Remediation
- Upgrade to Ghost 6.19.1 or later immediately.
- Rotate all Admin API keys and Content API keys.
- Audit all published posts for injected JavaScript content.
- Review Ghost access logs for Content API abuse patterns.
- Notify users who visited your site between May 7 and the date you patched — their devices may have been targeted by ClickFix.
- Block
clo4shara[.]xyzandweb-telegram[.]ugat the network perimeter.
← Back to the Security Roundup: Week of May 28, 2026