#0001
`Ghost CMS` Sites Hit by `ClickFix` Campaign via Critical CVE
60radar
Ghost CMSOpen-source CMS — supports newsletters and memberships
A critical CMS flaw is being used to turn legitimate sites into fake security-check traps. If you run Ghost, patch and audit immediately.
- Attackers abused
CVE-2026-26980, described as a criticalGhost CMSvulnerability; public disclosure quickly became live exploitation. - More than 700 sites were reportedly infected, so this has moved beyond theoretical risk into active campaign territory.
ClickFixtricks visitors with fake security verification flows; compromised content can damage trust even if your app backend stays intact.
Source: news.hada.io/topic?id=29916Read original →
