Summary

A critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980, CVSS 9.4) has been actively exploited to compromise over 700 websites, including sites belonging to Harvard, Oxford, DuckDuckGo, and organizations across blockchain, AI, SaaS, and financial technology sectors.

According to QiAnXin XLab, attackers exploited the flaw — originally discovered by Anthropic’s Claude AI — to extract Admin API Keys without authorization, then used Ghost’s Admin API to inject malicious JavaScript loaders at the bottom of published articles. The injected code fuels “ClickFix” attacks, a social engineering technique that tricks users into executing malicious commands via fake CAPTCHA pages.

The vulnerability was patched in Ghost version 6.19.1 back in February 2026, but the campaign — first detected on May 7 — demonstrates that hundreds of Ghost installations remain unpatched months later. At least two distinct threat clusters are behind the campaign, with some sites being compromised within a single day of being targeted.

Source

📰 The Hacker News — Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

📰 QiAnXin XLab — Full Technical Analysis

Commentary

There’s a bitter irony here: the vulnerability was found by an AI model (Claude), patched three months ago, and is now being mass-exploited because organizations didn’t update. This is exactly the scenario the ECB is warning banks about — AI accelerates vulnerability discovery, but patching cadence hasn’t kept pace. When Harvard and Oxford are among the compromised sites, it’s clear that even well-resourced institutions are failing at basic patch management.

The ClickFix technique continues to prove devastatingly effective because it weaponizes user trust in legitimate websites. Visitors to a compromised Harvard blog have no reason to suspect the CAPTCHA prompt is malicious. The attackers’ use of commercial cloaking services like Adspect to evade security scanners makes detection even harder, creating a two-tier web where researchers see clean pages while real users get served malware.

By Allan