Ghost CMS CVE-2026-26980 (CVSS 9.4): unauthenticated SQLi weaponized at scale — 700+ developer and tech community sites backdoored, serving ClickFix malware to every visitor
CVE-2026-26980 is a CVSS 9.4 unauthenticated blind SQL injection in Ghost CMS (v3.24.0–6.19.0) that exposes the site's Admin API key in a single crafted request — no account required — and enables bulk article backdooring via the Ghost Admin API. An XLab-documented exploitation campaign has compromised 700+ websites across universities (Harvard, Oxford), AI and SaaS companies, and DuckDuckGo, injecting malicious JavaScript loaders into published articles that serve fake CAPTCHA (ClickFix) pages to every real visitor, prompting them to paste attacker-controlled shell commands into their terminal. Developers are the downstream targets here — patch Ghost to 6.19.1 immediately, audit your published articles for injected `<script>` tags at page bottom, and if you've executed a browser-prompted 'fix' command this week, rotate all local developer credentials and review shell history.