Signal

Over 700 education and tech websites hijacked via Ghost CMS vulnerability in ClickFix malware campaign

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-26 10:46 UTCUpdated 2026-05-26 15:50 UTC
rss
cveexploitsmalwareincident_response
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
700+ education and tech websites hijacked in huge ClickFix malware campaign
Malwarebytes Threat Analysis · News · malwarebytes.com · 2026-05-26 10:46 UTC
limited source diversity in top sources
Overview

A critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS versions 3.24.0 to 6.19.0 has been exploited to compromise more than 700 legitimate websites, including those of universities and tech companies.

Entities
Ghost CMSCloudflare
Score total
0.83
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • The exploitation is currently active, affecting hundreds of legitimate sites across education and tech sectors.
  • The vulnerability affects multiple recent versions of Ghost CMS, indicating a broad attack surface.
  • Awareness and mitigation efforts are critical to prevent further infections and protect users.
Why it matters
  • The vulnerability allows attackers to hijack trusted websites, increasing the reach and credibility of malware campaigns.
  • Users are tricked into running malicious commands, leading to potential system compromise and data loss.
  • The scale of the campaign highlights ongoing risks in widely used CMS platforms and the need for timely patching.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • Attackers exploited CVE-2026-26980 in Ghost CMS to hijack over 700 websites and inject malware via fake Cloudflare verification prompts.
How sources frame it
  • Malwarebytes Threat Analysis: neutral
All evidence
All evidence
Ghost CMS vulnerability exploited in large-scale campaign
SC Media · scworld.com · 2026-05-26 15:50 UTC
700+ education and tech websites hijacked in huge ClickFix malware campaign
Malwarebytes Threat Analysis · malwarebytes.com · 2026-05-26 10:46 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • SC Media (1)
  • Malwarebytes Threat Analysis (1)
Top origin domains (this list)
  • scworld.com (1)
  • malwarebytes.com (1)