Sources: 

A recently identified SQL injection vulnerability (CVE-2026-26980) in the Ghost content management system has led to large-scale cyberattacks impacting over 700 websites globally. Attackers are exploiting this unpatched vulnerability to push malware onto visitors' computers through deceptive prompts.
According to
cybersecurity researchers from Qianxin, the flaw can be exploited by unauthenticated attackers enabling them to extract sensitive data from vulnerable Ghost databases. The campaign primarily targets
High-trust institutions like Harvard University and DuckDuckGo, which have confirmed breaches.
Qianxin first noted compromised sites in early May and began monitoring the situation closely. They observed that despite a patch being released on
February 19, 2026, many sites remained unprotected. Researchers from
XLab corroborated Qianxin's findings, reaching out to affected organizations on
May 10, 2026. By
May 21, many of these facilities had yet to respond, indicating either a lack of awareness or readiness to address the attacks.
The CVSS score for this vulnerability stands at
9.4, classification as critical. Attackers have been using a counterfeit
Cloudflare verification prompt to distribute malware undetected. As the security landscape evolves, the need for timely updates and awareness around vulnerabilities like CVE-2026-26980 becomes crucial to safeguarding sensitive data.
Sources: 
A recently patched SQL injection vulnerability (CVE-2026-26980) in the Ghost content management system has been exploited in mass cyberattacks targeting over 700 websites, including those of Harvard University and DuckDuckGo, according to cybersecurity researchers from Qianxin.