Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
2026-05-25T13:24:20Z•0a4ee3111f1b50450815472c13b6af4aab0d0e44058bdceeb5c294c39ab2511f
active-exploitationcisa-kevciscoclickfixcpanelcrates.iocredential-stealerdrupalghost-cmsgithub-breachlaravel-langlazaruslinux-kernelliteSpeedmegalodonmicrosoft-defendernpmpackagistpypiremotepesql-injectionsupply-chainvs-code-extension
What happened
Multiple high- and critical-severity vulnerabilities and active campaigns are impacting web platforms, supply chains, and enterprise software. Threat actors are actively exploiting Ghost CMS (CVE-2026-26980) via an unauthenticated SQL injection to hijack 700+ sites for ClickFix attacks. Other actively exploited or high-severity flaws include LiteSpeed cPanel plugin (CVE-2026-48172, CVSS 10.0) enabling root script execution and Drupal Core SQL injection (CVE-2026-9082) added to CISA's KEV. Cisco Secure Workload (CVE-2026-20223, CVSS 10.0) was patched, and Microsoft disclosed active exploitation
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0a4ee3111f1b50450815472c13b6af4aab0d0e44058bdceeb5c294c39ab2511f
- Enrichment time
- 2026-05-25T13:24:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.