Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
BleepingComputer
Security 2 months ago

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

By Bill Toulas

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. [...]

More from BleepingComputer

Leaving Threaticon

This link opens an external site that isn't part of the platform.