Ghost CMS ClickFix Poisoning Hits 700+ Sites
Ghost CMS ClickFix Poisoning Hits 700+ Sites
Attackers exploited Ghost CMS CVE-2026-26980 to steal admin API keys and inject ClickFix scripts into 700+ sites. Ghost operators should update, rotate credentials, clean pages, and audit logs.
Don't miss what's next. Subscribe to The Daily Cyber:
