CVE-2026-26980: Ghost CMS SQL Injection Actively Exploited to Hijack 700+ Sites for ClickFix Attacks

Technical breakdown of the Ghost CMS SQL injection exploited at scale to inject fake browser update (ClickFix) malware into 700+ websites.

CVE-2026-26980: Ghost CMS SQL Injection Actively Exploited to Hijack 700+ Sites for ClickFix Attacks
📌
Security Roundup Series: Week of May 28, 2026 • 4 min read deep dive
🚨
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-26980 Severity: CVSS 9.8 Status: ⚠️ Mass In-The-Wild Exploitation (ClickFix Malware) Target Component: Ghost CMS

CVE-2026-26980 (CVSS 9.4) is an SQL injection vulnerability in Ghost CMS's unauthenticated Content API, patched in version 6.19.1 in February 2026. Attackers began exploiting it at scale on May 7, 2026, and as of May 25, QiAnXin XLab had confirmed more than 700 websites compromised — spanning universities, blockchain companies, SaaS providers, security research firms, media, and fintech.

Vulnerability

The vulnerability lives in Ghost's unauthenticated Content API. By injecting a crafted SQL payload, an unauthenticated attacker can read arbitrary data from the database — including the site's Admin API key. The Admin API key grants full control over the Ghost instance: creating, modifying, and deleting posts and pages.

Attack Chain

  1. Attacker sends crafted SQL payload to the unauthenticated Content API endpoint.
  2. Admin API key is extracted from the database response.
  3. Attacker calls the Ghost Admin API to retrieve all published posts.
  4. Malicious JavaScript loader (<script src="...">) is injected at the bottom of every article in bulk via the Admin API.
  5. The loader fetches the main payload from clo4shara[.]xyz/11z77u3.php at runtime.
  6. The PHP script (powered by the Adspect cloaking service) fingerprints each visitor, serving real victims a fake CAPTCHA page via an iframe.
  7. The CAPTCHA page triggers a ClickFix attack: victims are instructed to open the Windows Run dialog and paste a Base64-encoded PowerShell command.
  8. The command downloads and executes a ZIP archive containing a Windows batch script.
  9. The batch script downloads a DLL via PowerShell, launches it with rundll32.exe, and opens a decoy webpage.
  10. Subsequent iterations replaced the DLL with a JavaScript payload that installs a modified Grape desktop client achieving persistence and polling web-telegram[.]ug every 30 seconds for C2 commands.

Affected Versions

All Ghost CMS versions prior to 6.19.1. The vulnerability was originally discovered by Anthropic's Claude Mythos AI system.

IOCs

  • C2/loader: clo4shara[.]xyz
  • C2/persistence: web-telegram[.]ug
  • Cloaking: Adspect commercial cloaking service
  • Two distinct threat clusters identified by QiAnXin XLab

Detection

Review Ghost access logs for unusual Content API queries with abnormal parameters. Look for bulk PUT /ghost/api/admin/posts/{id}/ requests following API key extraction. Inspect all published articles for injected <script> tags at the bottom of article HTML.

Remediation

  • Upgrade to Ghost 6.19.1 or later immediately.
  • Rotate all Admin API keys and Content API keys.
  • Audit all published posts for injected JavaScript content.
  • Review Ghost access logs for Content API abuse patterns.
  • Notify users who visited your site between May 7 and the date you patched — their devices may have been targeted by ClickFix.
  • Block clo4shara[.]xyz and web-telegram[.]ug at the network perimeter.

← Back to the Security Roundup: Week of May 28, 2026


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther