Ghost CMS vulnerability CVE-2026-26980 exploited in mass attacks to hijack over 700 sites, including Harvard and DuckDuckGo — active malware distribution reported

A vulnerability in the Ghost CMS, CVE-2026-26980, has allowed attackers to exploit over 700 websites since early May 2026. Major organizations, including Harvard University and DuckDuckGo, have been compromised, with cybercriminals using these sites to distribute malware.

Sources:
SecurityWeekTech Times
Trending 7m ago
Tab background
Sources: SecurityWeekTech Times
A recently identified SQL injection vulnerability (CVE-2026-26980) in the Ghost content management system has led to large-scale cyberattacks impacting over 700 websites globally. Attackers are exploiting this unpatched vulnerability to push malware onto visitors' computers through deceptive prompts.

According to cybersecurity researchers from Qianxin, the flaw can be exploited by unauthenticated attackers enabling them to extract sensitive data from vulnerable Ghost databases. The campaign primarily targets High-trust institutions like Harvard University and DuckDuckGo, which have confirmed breaches.

Qianxin first noted compromised sites in early May and began monitoring the situation closely. They observed that despite a patch being released on February 19, 2026, many sites remained unprotected. Researchers from XLab corroborated Qianxin's findings, reaching out to affected organizations on May 10, 2026. By May 21, many of these facilities had yet to respond, indicating either a lack of awareness or readiness to address the attacks.

The CVSS score for this vulnerability stands at 9.4, classification as critical. Attackers have been using a counterfeit Cloudflare verification prompt to distribute malware undetected. As the security landscape evolves, the need for timely updates and awareness around vulnerabilities like CVE-2026-26980 becomes crucial to safeguarding sensitive data.
Sources: SecurityWeek
A recently patched SQL injection vulnerability (CVE-2026-26980) in the Ghost content management system has been exploited in mass cyberattacks targeting over 700 websites, including those of Harvard University and DuckDuckGo, according to cybersecurity researchers from Qianxin.
Section 1 background
The Headline

Mass attacks exploit Ghost CMS vulnerability

Key Facts
  • Ghost CMS vulnerability CVE-2026-26980 has been exploited in mass attacks against unpatched instances, affecting over 700 websites, including those of major organizations like Harvard and DuckDuckGo.SecurityWeekTech Times
  • A patch for this vulnerability has been available since February 19, 2026, yet many sites remain unpatched.Tech Times
  • Qianxin first identified compromised websites in early May 2026.SecurityWeek
  • XLab began contacting affected websites on May 10, 2026, but by May 21, most notifications had received no response.Tech Times
Section 2 background
Background Context

Context on the Ghost CMS vulnerability

Key Facts
  • The vulnerability is an SQL injection flaw that can be exploited by unauthenticated attackers to extract sensitive data from the Ghost database.SecurityWeek
  • The vulnerability carries a CVSS score of 9.4, indicating a Critical rating and requiring no authentication to exploit.Tech Times
Article not found
CuriousCats.ai

Article

Source Citations