A large-scale cyberattack has compromised more than 700 legitimate websites by exploiting a critical vulnerability in Ghost CMS, enabling attackers to distribute malware through trusted domains. The campaign leverages CVE-2026-26980, a high-severity SQL injection vulnerability with a CVSS score of 9.4, affecting Ghost versions 3.24.0 through 6.19.0.
The flaw allows unauthenticated attackers to extract administrative API keys from Ghost’s Content API. Once obtained, these keys enable attackers to inject malicious JavaScript into website content, giving them effective control over pages and posts. Victims visiting compromised sites are presented with fake Cloudflare verification or CAPTCHA pages that instruct them to copy and paste commands into Windows Run or PowerShell, unknowingly installing malware.
The campaign has impacted a wide range of trusted organizations, including universities, technology companies, AI platforms, fintech firms, SaaS providers, and media websites. Well-known institutions such as Harvard, Oxford, and Auburn universities have reportedly been affected, increasing the likelihood that users will trust the malicious prompts.
Researchers first observed exploitation activity in early May 2026, despite a security patch being released in February 2026 with Ghost version 6.19.1. The incident highlights the dangers of delayed patch management, as many organizations failed to update vulnerable systems.
Security experts recommend that website administrators immediately upgrade to the latest Ghost version, rotate API keys, review website content for unauthorized scripts, and conduct comprehensive security audits. Users should never copy and paste commands from websites, even trusted ones, and should treat unexpected CAPTCHA or security verification prompts with caution.
The attack underscores the growing success of ClickFix campaigns, which combine technical vulnerabilities with social engineering to exploit both systems and human trust. As cybercriminals increasingly target content management systems, timely patching and user awareness remain critical defenses.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.
