CVE-2026-26980Active Exploitation(ghost / ghost)

CRITICALCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 39 mentions and remains active

Immediate actions

  • Patch ghost ghost systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ghost

Threat summary

  • Active exploitation appears in 117 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 165 mentions across 44 observed days

What's happening

  • Active exploitation reported across 117 signals
  • Exploit tool or code specified in 10 signals
  • PoC mentioned or linked in 15 signals
  • Patch or workaround mentioned in 39 signals
  • Technical details provided in 102 signals
  • Disclosure: 22 classified signals
  • General: 9 classified signals
  • Peaked 26d ago at 39 mentions (2026-05-25); latest day: 1
  • 165 total mentions across 44 days

Affected systems

Vendors
Products
ghost

Deep dive

Activity timeline165 mentions / 44d
010202939Mentions · 2026-02-19: 1Mentions · 2026-02-20: 7Mentions · 2026-02-25: 1Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1Mentions · 2026-03-31: 3Mentions · 2026-04-01: 1Mentions · 2026-04-06: 1Mentions · 2026-04-17: 2Mentions · 2026-04-19: 1Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1Mentions · 2026-05-21: 6Mentions · 2026-05-22: 3Mentions · 2026-05-23: 1Mentions · 2026-05-24: 15Mentions · 2026-05-25: 39Mentions · 2026-05-26: 26Mentions · 2026-05-27: 5Mentions · 2026-05-28: 3Mentions · 2026-05-29: 5Mentions · 2026-05-31: 2Mentions · 2026-06-01: 1Mentions · 2026-06-02: 3Mentions · 2026-06-03: 2Mentions · 2026-06-05: 2Mentions · 2026-06-07: 1Mentions · 2026-06-08: 5Mentions · 2026-06-11: 1Mentions · 2026-06-16: 1Mentions · 2026-06-24: 1Mentions · 2026-06-25: 1Mentions · 2026-06-27: 2Mentions · 2026-07-08: 1Mentions · 2026-07-14: 1Mentions · 2026-07-22: 1Mentions · 2026-07-24: 2Mentions · 2026-08-03: 8Mentions · 2026-08-20: 1Mentions · 2026-08-28: 1Mentions · 2026-09-22: 1Mentions · 2026-09-23: 1Mentions · 2026-10-07: 1PoC Mentioned / Linked · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-17: 2PoC Mentioned / Linked · 2026-05-09: 1PoC Mentioned / Linked · 2026-05-22: 2PoC Mentioned / Linked · 2026-05-26: 2PoC Mentioned / Linked · 2026-05-29: 2PoC Mentioned / Linked · 2026-06-27: 2PoC Mentioned / Linked · 2026-07-22: 1PoC Mentioned / Linked · 2026-08-03: 2Exploit Tool / Code · 2026-04-17: 2Exploit Tool / Code · 2026-05-09: 1Exploit Tool / Code · 2026-05-24: 1Exploit Tool / Code · 2026-05-26: 2Exploit Tool / Code · 2026-06-27: 2Exploit Tool / Code · 2026-07-22: 1Exploit Tool / Code · 2026-08-03: 1Active Exploitation · 2026-04-19: 1Active Exploitation · 2026-05-21: 5Active Exploitation · 2026-05-22: 3Active Exploitation · 2026-05-23: 1Active Exploitation · 2026-05-24: 14Active Exploitation · 2026-05-25: 37Active Exploitation · 2026-05-26: 23Active Exploitation · 2026-05-27: 5Active Exploitation · 2026-05-28: 1Active Exploitation · 2026-05-29: 4Active Exploitation · 2026-05-31: 2Active Exploitation · 2026-06-01: 1Active Exploitation · 2026-06-02: 3Active Exploitation · 2026-06-03: 2Active Exploitation · 2026-06-05: 2Active Exploitation · 2026-06-07: 1Active Exploitation · 2026-06-08: 2Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-07-14: 1Active Exploitation · 2026-07-24: 1Active Exploitation · 2026-08-03: 3Active Exploitation · 2026-08-20: 1Active Exploitation · 2026-08-28: 1Active Exploitation · 2026-09-22: 1Active Exploitation · 2026-09-23: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 4Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-05-22: 2Patch / Workaround · 2026-05-24: 5Patch / Workaround · 2026-05-25: 7Patch / Workaround · 2026-05-26: 8Patch / Workaround · 2026-05-27: 2Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-05-29: 1Patch / Workaround · 2026-05-31: 1Patch / Workaround · 2026-06-02: 1Patch / Workaround · 2026-06-05: 1Patch / Workaround · 2026-06-07: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 7Technical Details · 2026-02-25: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 3Technical Details · 2026-04-01: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-19: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-22: 2Technical Details · 2026-05-24: 14Technical Details · 2026-05-25: 20Technical Details · 2026-05-26: 16Technical Details · 2026-05-27: 2Technical Details · 2026-05-28: 3Technical Details · 2026-05-29: 1Technical Details · 2026-06-02: 3Technical Details · 2026-06-05: 2Technical Details · 2026-06-07: 1Technical Details · 2026-06-08: 4Technical Details · 2026-06-11: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-27: 2Technical Details · 2026-07-08: 1Technical Details · 2026-07-22: 1Technical Details · 2026-07-24: 2Technical Details · 2026-08-03: 5Technical Details · 2026-09-23: 102-1903-3004-1705-1005-2405-2806-0206-0806-2507-2208-2810-07
Signal classification6 categories
Active Exploitation
11670.7%
Disclosure
2213.4%
General
95.5%
Patch
84.9%
PoC
74.3%
Exploit
21.2%
Referenced assets128 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-191
Patch1
2026-02-207
Disclosure4Patch3
2026-02-251
Disclosure1
2026-03-281
Disclosure1
2026-03-301
Disclosure1
2026-03-313
Disclosure3
2026-04-011
PoC1
2026-04-061
Disclosure1
2026-04-172
PoC2
2026-04-191
Active Exploitation1
2026-05-081
Disclosure1
2026-05-091
Exploit1
2026-05-101
General1
2026-05-216
Active Exploitation5General1
2026-05-223
Active Exploitation3
2026-05-231
Active Exploitation1
2026-05-2415
Active Exploitation14Disclosure1
2026-05-2539
Active Exploitation37General1Patch1
2026-05-2626
Active Exploitation23Exploit1General1Patch1
2026-05-275
Active Exploitation5
2026-05-283
Active Exploitation1Disclosure2
2026-05-295
Active Exploitation3General1Patch1
2026-05-312
Active Exploitation2
2026-06-011
Active Exploitation1
2026-06-023
Active Exploitation3
2026-06-032
Active Exploitation2
2026-06-052
Active Exploitation2
2026-06-071
Active Exploitation1
2026-06-085
Active Exploitation2Disclosure3
2026-06-111
General1
2026-06-161
Patch1
2026-06-241
General1
2026-06-251
Active Exploitation1
2026-06-272
PoC2
2026-07-081
Disclosure1
2026-07-141
Active Exploitation1
2026-07-221
PoC1
2026-07-242
Active Exploitation1Disclosure1
2026-08-038
Active Exploitation3Disclosure2General2PoC1
2026-08-201
Active Exploitation1
2026-08-281
Active Exploitation1
2026-09-221
Active Exploitation1
2026-09-231
Active Exploitation1
Full discourse20 posts
  • International Cyber Digest@IntCyberDigest
    Active Exploitation

    ‼️🚨 Over 700 Ghost CMS sites, including Harvard, Oxford, and Auburn, were compromised through an unauthenticated SQL injection (CVE-2026-26980). Attackers pulled Admin API Keys and turned every site into a ClickFix delivery vector via fake Cloudflare "verify you are human" pages. Patch was out February 19. Most never applied it.

    Post summary

    CVE-2026-26980 enabled unauthenticated SQL injection that was actively exploited on over 700 Ghost CMS sites, with attackers using admin keys to deploy malicious Cloudflare verification pages; a patch was released on February 19 but many sites remained unpatched.

    15991673229273.6K
    193.5K followersView on X
  • Md Ismail Šojal 🕷️@0x0SojalSec
    Disclosure

    Nicolas Carlini showed Claude can find 0-DAY vulnerabilities, in a live conference demo. it found Autonomously finding a blind SQL injection zero-day (CVE-2026-26980) in Ghost CMS, extracting stole admin API keys without authentication in roughly 90 minutes, marking the platform's first critical vulnerability after 20 years and 50,000+ GitHub stars. Then did the exact same thing to the Linux kernel, it few months older video

    Post summary

    The passage reports that Claude was used to autonomously discover and demonstrate a blind SQL injection zero‑day (CVE‑2026‑26980) in Ghost CMS, without mentioning exploitation tools, patches, or active attacks.

    233120524015.8K
    54.4K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-26980: Ghost CMS SQL Injection PoC PoC: https://github.com/gagaltotal/CVE-2026-26980-Ghost-CMS-Api https://t.co/nHGQRFzeU0

    Post summary

    A proof‑of‑concept repository for CVE-2026-26980 (Ghost CMS SQL injection) is publicly available, confirming the vulnerability but lacking evidence of active exploitation or patching.

    228123214825.2K
    226.8K followersView on X
  • Eric Parker@EricParker
    Active Exploitation

    "Yuniko Software", publishers of a Minecraft MCP server and a few other AI tools had their ghost CMS site compromised with CVE-2026-26980 so it is now displaying a new clickfix attack. I tried to open a github issue but instead of removing the malware, they deleted my issue. 🤦 https://t.co/ppKpujv2Rp

    Post summary

    Yuniko Software’s Ghost CMS was compromised via CVE-2026-26980, and the site is now delivering clickfix malware—indicating active exploitation.

    450192169.7K
    9.9K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Hackers breached 700+ Ghost CMS websites to serve ClickFix malware attacks. Read 🠒 https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html The attackers exploited critical flaw CVE-2026-26980 to steal admin API keys and inject malicious JavaScript into legitimate sites, including university, AI, blockchain, and fintech platforms. Visitors were shown fake CAPTCHA pages that tricked them into running malware. #Cybersecurity #Malware

    Post summary

    Hackers are actively exploiting CVE-2026-26980 on over 700 Ghost CMS sites, stealing admin API keys and delivering malware via injected JavaScript and fake CAPTCHA pages.

    43541382619.7K
    1.9M followersView on X
  • Clandestine@akaclandestine
    Exploit

    GitHub - vognik/CVE-2026-26980: 💣 Exploit for CVE-2026-26980 — 👻 Ghost CMS Unauthenticated SQLi via Content API · GitHub https://github.com/vognik/CVE-2026-26980

    Post summary

    The GitHub repository hosts an exploit for CVE-2026-26980, demonstrating an unauthenticated SQL injection via Ghost CMS’s Content API, but does not discuss real‑world exploitation or patches.

    015041253.8K
    62.5K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Ghost CMS CVE-2026-26980, reproducing with raptor https://github.com/gadievron/raptor https://t.co/ZjkLsbhnFB

    Post summary

    The Ghost CMS vulnerability CVE-2026-26980 is being reproduced using the Raptor tool, with a PoC code publicly available on GitHub.

    09036193.1K
    158.1K followersView on X
  • Xlab@Xlab_qax
    Active Exploitation

    700+ Ghost CMS sites compromised via CVE-2026-26980 (SQLi → Admin API Key theft) and weaponized for ClickFix attacks. Victims include Harvard, Oxford, Auburn and more. Two threat actors now fighting over the same sites. https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/

    Post summary

    The CVE-2026-26980 SQL injection flaw is actively exploited in the wild, compromising over 700 Ghost CMS sites—including major universities—and is being leveraged for ClickFix attacks.

    011127169.6K
    995 followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    Ghost CMSの重大SQLインジェクション脆弱性「CVE-2026-26980」が大規模悪用され、700以上のサイトへ不正JavaScriptが埋め込まれている。偽Cloudflare認証を使うClickFix攻撃へ誘導される。 影響を受けるのはGhost CMS 3.24.0〜6.19.0。脆弱性を悪用されると、認証不要でデータベース情報や管理用APIキーを窃取できる。攻撃者は取得した権限を使い、記事ページへ悪性JavaScriptを挿入していた。 XLabによれば、被害は大学、AI企業、金融、メディアなど広範囲に及び、Harvard University、Oxford University、DuckDuckGo関連サイトでも悪性コード確認が報告された。 感染ページでは、まず軽量JavaScriptローダーが動作し、訪問者情報を収集。その後、条件に一致した利用者だけに偽Cloudflare確認画面をiframe経由で表示する。被害者へ「人間確認」を装ってWindowsコマンド入力を要求し、DLLローダーやJavaScriptドロッパー、「UtilifySetup.exe」と呼ばれるElectron製マルウェアなどを感染させる。 この脆弱性は2026年2月19日にGhost CMS 6.19.1で修正済みだったが、多数サイトが更新を怠っていた。SentinelOneは2月末時点で既に悪用を確認しており、複数攻撃グループが同一サイトへ再感染を繰り返していたという。 管理者には6.19.1以降への緊急更新に加え、APIキーの全ローテーション、不正スクリプト確認、APIログ30日以上保存が推奨されている。 https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/

    Post summary

    CVE‑2026‑26980, a critical SQL injection in Ghost CMS, has been actively exploited on over 700 sites, including major universities, with attackers injecting malicious JavaScript via a ClickFix campaign. A patch (6.19.1) exists and urgent updates are advised.

    0502493.2K
    14.5K followersView on X
  • blackorbird@blackorbird
    Active Exploitation

    Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/ https://t.co/w3IoHeZ4kd

    Post summary

    The post reports that Ghost CMS has been widely compromised via CVE‑2026‑26980 and is currently being leveraged in active ClickFix attacks, though it provides no specific technical details or mitigations.

    1602193.2K
    42.9K followersView on X
  • Virus Bulletin@virusbtn
    Active Exploitation

    XLab researchers show how threat actors exploited CVE-2026-26980 to compromise Ghost CMS, causing numerous websites to become accomplices in ClickFix attacks. https://blog.xlab.qianxin.com/ghost-cms-page-poisoning-cve-2026-26980/ https://t.co/SGklq26bvS

    Post summary

    XLab researchers report that threat actors are actively exploiting CVE-2026-26980 in Ghost CMS, enabling ClickFix attacks that compromise numerous websites.

    0601881.3K
    61.4K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab https://github.com/dinosn/ghost-cve-2026-26980

    Post summary

    A GitHub repository hosts a lab demonstrating an SQL injection vulnerability in Ghost CMS’s Content API (CVE-2026-26980).

    0601481.8K
    158.1K followersView on X
  • International Cyber Digest@IntCyberDigest
    Active Exploitation

    Source: https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/

    Post summary

    The blog highlights that Ghost CMS has been broadly compromised via CVE-2026-26980, with the flaw currently being used to fuel ClickFix attacks, indicating active exploitation in the wild.

    1101457.4K
    193.5K followersView on X
  • Silicon Valley Fodder@Playerinthgame
    Disclosure

    Heads up about a critical SQL injection vuln in Ghost CMS affecting Harvard, Oxford, and DuckDuckGo among others CVE-2026-26980 https://t.co/ipJF7BhB3k

    Post summary

    A brief alert on Twitter highlights a critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) that has reportedly affected notable institutions, but it does not provide PoC, exploit code, active exploitation evidence, or patch information.

    130112675
    11.5K followersView on X
  • Cloudflare Changelog@CFchangelog
    Patch

    WAF release 2026-06-15 is here. We added managed rules to block the Ghost CMS SQLi vulnerability CVE-2026-26980. Protect your installations at the edge. https://developers.cloudflare.com/changelog/post/2026-06-15-waf-release/

    Post summary

    Cloudflare rolled out new WAF rules to block the Ghost CMS SQLi vulnerability CVE-2026-26980, effectively providing a patch for affected installations.

    1101311.3K
    5.0K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html

    Post summary

    CVE-2026-26980 is being actively exploited, with attackers hijacking over 700 Ghost CMS sites to run ClickFix phishing campaigns.

    0301021.6K
    158.6K followersView on X
  • Bert-Jan 🛡️@BertJanCyber
    General

    More details: https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/

    Post summary

    The post links to a blog article describing a Ghost CMS vulnerability but provides no explicit details, PoC code, or evidence of exploitation or mitigation.

    020741.0K
    4.5K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Hackers are actively exploiting a critical Ghost CMS SQL flaw (CVE-2026-26980) to hijack 700+ websites and serve fake Cloudflare ClickFix malware overlays. #GhostCMS #CVE202626980 #Cybersecurity #ClickFix #Malware #Infosec2026 #SQLInjection https://meterpreter.org/ghost-cms-cve-2026-26980-exploitation-clickfix-fake-captcha-attacks/ https://t.co/ykIhER2P87

    Post summary

    The tweet reports that hackers are actively exploiting CVE‑2026‑26980 in Ghost CMS, hijacking over 700 sites and delivering fake Cloudflare ClickFix malware overlays, with a link to an exploitation guide.

    03072672
    12.5K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    XLab uncovers a massive Ghost CMS poisoning campaign utilizing CVE-2026-26980 to launch FakeCaptcha attacks. Learn how to secure your site. #Cybersecurity #GhostCMS #Infosec #Malware #SQLInjection #ClickFix https://securityonline.info/ghost-cms-poisoning-campaign-cve-2026-26980/ https://t.co/cBJGYmRgg6

    Post summary

    The post highlights a widespread Ghost CMS poisoning campaign that exploits CVE-2026-26980 to deliver FakeCaptcha attacks, urging site owners to take security precautions.

    01080699
    12.5K followersView on X
  • Anavem.com@Anavem_
    Active Exploitation

    Attackers exploit CVE-2026-26980 SQL injection flaw in Ghost CMS to inject malicious JavaScript triggering ClickFix campaigns. https://www.anavem.com/en/news/cybersecurity/ghost-cms-hit-by-critical-sql-injection-exploits

    Post summary

    The post reports that attackers are actively exploiting CVE-2026-26980, a Ghost CMS SQL injection, to inject malicious JavaScript that fuels ClickFix campaigns.

    020601.2K
    168 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appghostghost-node.js-

Explore more