A large-scale campaign is exploiting a critical SQL injection flaw in Ghost CMS to inject malicious JavaScript that pushes ClickFix attack flows, with XLab researchers confirming more than 700 affected domains including university portals, media outlets and fintech sites.
KEY FACTS
- Vulnerability CVE-2026-26980 affects Ghost 3.24.0 through 6.19.0.
- Impact Attackers can read database data, including admin API keys.
- Scale More than 700 domains were affected, according to the report.
- Targets The campaign touched universities, AI and SaaS firms, media, fintech and security sites.
A technical analysis from XLab said attackers used the SQL injection flaw to steal admin API keys and then modify article pages with malicious JavaScript. The code acted as a loader that pulled second-stage content from attacker infrastructure and fingerprinted visitors before serving the next stage.
Visitors judged to be suitable targets were shown a fake Cloudflare verification prompt inside an iframe. The lure asked them to paste a command into Windows Command Prompt, which then dropped a payload.
The report said the campaign included multiple payload types, including DLL loaders, JavaScript droppers and an Electron-based sample named UtilifySetup.exe. It also said researchers saw at least two activity clusters, with some compromised sites reinfected after cleanup or one cluster removing the other’s script before adding its own.
Ghost released version 6.19.1 on February 19 to fix the issue, but many sites did not install the update. SentinelOne later published exploitation details on February 27 and detection guidance.
WHY IT MATTERS
The campaign shows how a CMS flaw can be turned into a broader delivery platform for malware and social engineering. Site operators running affected Ghost versions need to update, rotate exposed keys and review logs and injected scripts to reduce the risk of reinfection.

