CRITICAL: Ghost CMS SQL Injection Bug Turns Harvard, Oxford and 700 Other Sites Into ClickFix Launchpads
Threat actors are mass-exploiting CVE-2026-26980, a critical SQL injection bug in Ghost CMS, to harvest Admin API keys and inject ClickFix malware loaders into more than 700 hijacked sites including Harvard, Oxford, Auburn, and DuckDuckGo. A patch has been available in version 6.19.1 since February.