Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

2026-05-25T13:24:20Z0a4ee3111f1b50450815472c13b6af4aab0d0e44058bdceeb5c294c39ab2511f
active-exploitationcisa-kevciscoclickfixcpanelcrates.iocredential-stealerdrupalghost-cmsgithub-breachlaravel-langlazaruslinux-kernelliteSpeedmegalodonmicrosoft-defendernpmpackagistpypiremotepesql-injectionsupply-chainvs-code-extension

What happened

Multiple high- and critical-severity vulnerabilities and active campaigns are impacting web platforms, supply chains, and enterprise software. Threat actors are actively exploiting Ghost CMS (CVE-2026-26980) via an unauthenticated SQL injection to hijack 700+ sites for ClickFix attacks. Other actively exploited or high-severity flaws include LiteSpeed cPanel plugin (CVE-2026-48172, CVSS 10.0) enabling root script execution and Drupal Core SQL injection (CVE-2026-9082) added to CISA's KEV. Cisco Secure Workload (CVE-2026-20223, CVSS 10.0) was patched, and Microsoft disclosed active exploitation

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
0a4ee3111f1b50450815472c13b6af4aab0d0e44058bdceeb5c294c39ab2511f
Enrichment time
2026-05-25T13:24:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.