Back to IntelRead Original Source
Intel Node
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
criticalvulnerability2026-05-24T14:12:32+00:00source excerpt
vulnerabilitycve
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.