Multiple reports say threat actors are exploiting a recently disclosed critical SQL injection flaw in Ghost CMS, tracked as CVE-2026-26980 (CVSS 9.4), in campaigns tied to “ClickFix” attacks. According to QiAnXin XLab, the campaign targets Ghost sites by abusing an SQL injection weakness in Ghost’s Content API. The attackers inject malicious JavaScript code intended to alter site behavior and trigger ClickFix attack flows.
One outlet reports the campaign is large-scale, using the vulnerability to inject JavaScript rather than limiting activity to data extraction. Another outlet describes evidence that more than 700 sites are being hijacked, with the injected script used to redirect or drive user actions consistent with ClickFix techniques.
The reporting is consistent that the flaw is exploited without requiring authentication, enabling an attacker to perform the injection remotely and at scale. The sources do not indicate that the attackers’ objective extends beyond fueling ClickFix activity using the compromised sites’ browsers.