Ghost CMS flaw abused to push ClickFix attacks on hundreds of sites

2026-05-26T02:51:42Z5eb28c9b5213adea6955d9b2e1e1585b010c1d9ff8d24c9e3804be719147d6ff
CISA KEVCVE-2026-26980CVE-2026-9082account takeoveractive exploitationanthropic project glasswingclickfixdata aggregationdrupalghost cmshosting takedownios 16kash patel site compromisemalware distributiononlyfanspatching gapreconstructed leaksserver seizuresql injectionstark industriesvulnerability discoverywhatsappzero-click

What happened

A batch of Security Affairs reports covering active exploitation, large-scale data aggregation, infrastructure takedowns, and vulnerability discovery: attackers are abusing a patched Ghost CMS flaw (CVE-2026-26980) to deliver ClickFix malware across 700+ unpatched sites (including universities); a 340M-onlyfans profile dataset is being sold that appears reconstructed from prior breaches/public data rather than a direct OnlyFans breach; a zero-click WhatsApp takeover is observed against iPhones on iOS 16 allowing account hijacks without linked devices or user interaction; the merchandise siteof

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
5eb28c9b5213adea6955d9b2e1e1585b010c1d9ff8d24c9e3804be719147d6ff
Enrichment time
2026-05-26T02:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.