Application SecurityIntermediate5 modules

Ghost CMS flaw abused to push ClickFix attacks on hundreds of sites

HackerLegend.com Threat IntelligenceOriginal Source

Threat Overview

Ghost CMS flaw CVE-2026-26980 exploited in ClickFix attacks on hundreds of sites, compromising universities and well-known organizations.

1

Threat Overview

Attackers are exploiting the patched Ghost CMS flaw CVE-2026-26980, compromising over 700 unpatched sites, including universities. This vulnerability allows threat actors to push ClickFix attacks. The flaw was fixed months ago, but many sites remain unpatched.
2

Key Intelligence Points

1. Ghost CMS is being exploited through the patched CVE-2026-26980 vulnerability.
2. Over 700 sites, including universities and well-known organizations, are affected, with many still unpatched.
3. Threat actors are pushing ClickFix attacks, which compromise sites and potentially spread malware.
4. Detection opportunities include identifying suspicious traffic patterns and unusual website behavior.
3

MITRE ATT&CK Techniques

T1190 - Exploit Public-Facing Application
4

Mitigation & Detection

Immediately patch Ghost CMS to the latest version to prevent exploitation of CVE-2026-26980.