PortsuppeApp
SearchSourcesAboutDE/EN

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

BleepingComputer·3d·Media

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. [...]

Categories cybersecurity · government-security · data-protection
Original source / advisory
Published
5/24/2026, 2:12:32 PM
Fetched
5/27/2026, 4:13:57 AM
Trust
media · 60/100
Language
en