Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

2026-05-25T01:23:28Z95e41b098d4bb2add34560061f7109956e35e96b2326436befce75165cae7888
botnetcomposercredential-stealercryptodrainerddosgithub-tagshosting-abuselaw-enforcementlinux-malwaremalwarepiracyremote-code-executionsql-injectionsupply-chainsupply-chain-tamperingtelco-targetingvulnerability-patchwindows-malwarezero-day

What happened

Multiple high-impact incidents and active exploits reported: a critical Ghost CMS SQL injection (CVE-2026-26980) is being exploited in a large ClickFix campaign to inject malicious JavaScript; Laravel Lang localization packages were hijacked via GitHub tags to distribute credential‑stealing malware through Composer; Trend Micro warned of an Apex One zero‑day actively exploited in the wild and Drupal is being targeted for a critical SQLi. Vendors (Ubiquiti, Cisco) patched maximum‑severity flaws, Google accidentally exposed details of an unfixed Chromium RCE issue, and Chinese actors deployednew

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
95e41b098d4bb2add34560061f7109956e35e96b2326436befce75165cae7888
Enrichment time
2026-05-25T01:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.