Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
2026-05-25T01:23:28Z•95e41b098d4bb2add34560061f7109956e35e96b2326436befce75165cae7888
botnetcomposercredential-stealercryptodrainerddosgithub-tagshosting-abuselaw-enforcementlinux-malwaremalwarepiracyremote-code-executionsql-injectionsupply-chainsupply-chain-tamperingtelco-targetingvulnerability-patchwindows-malwarezero-day
What happened
Multiple high-impact incidents and active exploits reported: a critical Ghost CMS SQL injection (CVE-2026-26980) is being exploited in a large ClickFix campaign to inject malicious JavaScript; Laravel Lang localization packages were hijacked via GitHub tags to distribute credential‑stealing malware through Composer; Trend Micro warned of an Apex One zero‑day actively exploited in the wild and Drupal is being targeted for a critical SQLi. Vendors (Ubiquiti, Cisco) patched maximum‑severity flaws, Google accidentally exposed details of an unfixed Chromium RCE issue, and Chinese actors deployednew
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 95e41b098d4bb2add34560061f7109956e35e96b2326436befce75165cae7888
- Enrichment time
- 2026-05-25T01:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.