International Cyber Digest[verified]@IntCyberDigestActive Exploitation
CVE-2026-26980 enabled unauthenticated SQL injection that was actively exploited on over 700 Ghost CMS sites, with attackers using admin keys to deploy malicious Cloudflare verification pages; a patch was released on February 19 but many sites remained unpatched.
Md Ismail Šojal 🕷️[verified]@0x0SojalSecDisclosure
The passage reports that Claude was used to autonomously discover and demonstrate a blind SQL injection zero‑day (CVE‑2026‑26980) in Ghost CMS, without mentioning exploitation tools, patches, or active attacks.
Eric Parker[verified]@EricParkerActive Exploitation
Yuniko Software’s Ghost CMS was compromised via CVE-2026-26980, and the site is now delivering clickfix malware—indicating active exploitation.
Clandestine[verified]@akaclandestineExploit
The GitHub repository hosts an exploit for CVE-2026-26980, demonstrating an unauthenticated SQL injection via Ghost CMS’s Content API, but does not discuss real‑world exploitation or patches.
Nicolas Krassas[verified]@DinosnPoC
The Ghost CMS vulnerability CVE-2026-26980 is being reproduced using the Raptor tool, with a PoC code publicly available on GitHub.
yousukezan[verified]@yousukezanActive Exploitation
CVE‑2026‑26980, a critical SQL injection in Ghost CMS, has been actively exploited on over 700 sites, including major universities, with attackers injecting malicious JavaScript via a ClickFix campaign. A patch (6.19.1) exists and urgent updates are advised.
blackorbird[verified]@blackorbirdActive Exploitation
The post reports that Ghost CMS has been widely compromised via CVE‑2026‑26980 and is currently being leveraged in active ClickFix attacks, though it provides no specific technical details or mitigations.
Nicolas Krassas[verified]@DinosnPoC
A GitHub repository hosts a lab demonstrating an SQL injection vulnerability in Ghost CMS’s Content API (CVE-2026-26980).