Global Ghost CMS flaw exploited to steal admin keys and push ClickFix scam

1 min read
Source: BleepingComputer
Global Ghost CMS flaw exploited to steal admin keys and push ClickFix scam
Photo: BleepingComputer
TL;DR Summary

A widespread campaign abused a critical Ghost CMS SQL injection (CVE-2026-26980) affecting versions 3.24.0–6.19.0 to read database data and steal admin API keys, then injects malicious JavaScript into articles. The loader fetches a second-stage payload that triggers a fake Cloudflare prompt and a ClickFix lure, leading victims to a Windows command prompt instruction and subsequent malware downloads. High-profile targets (Harvard, Oxford, Auburn, DuckDuckGo) were affected. Ghost released fix 6.19.1 on Feb 19, but many sites have not updated. Action items: upgrade to 6.19.1+, rotate all exposed keys, and review up to 30 days of admin API call logs to identify IoCs and remove injected scripts.

Share this article

Reading Insights

Total Reads

0

Unique Readers

6

Time Saved

3 min

vs 4 min read

Condensed

86%

731105 words

Want the full story? Read the original article

Read on BleepingComputer