Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

Threat actors are exploiting a critical Ghost CMS vulnerability to inject malicious JavaScript on more than 700 sites for ClickFix attacks, compromising sectors ranging from universities to fintech. The exploitation of Ghost CMS's vulnerability underscores the importance of promptly applying security patches and maintaining robust access controls to prevent unauthorized access.

https://meta-news.info/ver/ghost-cms-vuโ€ฆ