Ghost CMS flaw abused to push ClickFix attacks on hundreds of sites
2026-05-26T02:51:42Z•5eb28c9b5213adea6955d9b2e1e1585b010c1d9ff8d24c9e3804be719147d6ff
CISA KEVCVE-2026-26980CVE-2026-9082account takeoveractive exploitationanthropic project glasswingclickfixdata aggregationdrupalghost cmshosting takedownios 16kash patel site compromisemalware distributiononlyfanspatching gapreconstructed leaksserver seizuresql injectionstark industriesvulnerability discoverywhatsappzero-click
What happened
A batch of Security Affairs reports covering active exploitation, large-scale data aggregation, infrastructure takedowns, and vulnerability discovery: attackers are abusing a patched Ghost CMS flaw (CVE-2026-26980) to deliver ClickFix malware across 700+ unpatched sites (including universities); a 340M-onlyfans profile dataset is being sold that appears reconstructed from prior breaches/public data rather than a direct OnlyFans breach; a zero-click WhatsApp takeover is observed against iPhones on iOS 16 allowing account hijacks without linked devices or user interaction; the merchandise siteof
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 5eb28c9b5213adea6955d9b2e1e1585b010c1d9ff8d24c9e3804be719147d6ff
- Enrichment time
- 2026-05-26T02:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.