2026-05-25NOTABLEexploitedGhost CMS CVE-2026-26980 → ClickFix: the CMS-compromise-to-endpoint kill chain
Ghost CMS Content API unauthenticated SQLi (CVSS 9.4); ITW-exploited in ClickFix campaign; fixed 6.19.1
cve · CVE-2026-26980
Coverage
2
first 2026-05-25 → last 2026-05-31
Latest activity
2026-05-25
Ghost CMS CVE-2026-26980 → ClickFix: the CMS-compromise-to-endpoint kill chain
Peak priority
high
1 high · 1 notable
Targets
education
sectors: education, media, technology · regions: europe
Sources cited
11
4 hosts
Defender insights
What each entry about CVE-2026-26980 tells a defender to do, newest first.
Detection
Story timeline
- 2026-05-25Ghost CMS CVE-2026-26980 → ClickFix: the CMS-compromise-to-endpoint kill chain
- 2026-05-25CVE-2026-26980, Ghost CMS Content API: unauthenticated blind SQL injection in the slug filter, actively exploited
Hunting pivots
ATT&CK techniques (10 across 5 tactics)
10 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application · Content Injection
- ExecutionCommand and Scripting Interpreter · Command and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: Windows Command Shell · User Execution · User Execution: Malicious File
- StealthExecution Guardrails
- Credential AccessUnsecured Credentials
- Command and ControlIngress Tool Transfer · Content Injection
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-05-25/ghost-cms-cve-2026-26980-clickfix-the-cms-compromise-to-endp · ATT&CK page ↗
T1659Content Injection×1
Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic. Rather than luring victims to malicious payloads hosted on a compromised website (i.e., Drive-by Target followed by Drive-by Compromise), adversaries may initially access victims through compromised data-transfer channels where they can manipulate traffic and/or inject their own content. These compromised online network channels may also be used to deliver additional payloads (i.e., Ingress Tool Transfer) and other data to already compromised systems.
Evidence: 2026-05-25/ghost-cms-cve-2026-26980-clickfix-the-cms-compromise-to-endp · ATT&CK page ↗
Execution TA0002
T1059Command and Scripting Interpreter×1
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Evidence: 2026-05-25/ghost-cms-cve-2026-26980-clickfix-the-cms-compromise-to-endp · ATT&CK page ↗
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-05-25/ghost-cms-cve-2026-26980-clickfix-the-cms-compromise-to-endp · ATT&CK page ↗
T1059.003Command and Scripting Interpreter: Windows Command Shell×1
Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.
Evidence: 2026-05-25/ghost-cms-cve-2026-26980-clickfix-the-cms-compromise-to-endp · ATT&CK page ↗
T1204User Execution×1
An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.
Evidence: 2026-05-25/ghost-cms-cve-2026-26980-clickfix-the-cms-compromise-to-endp · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-05-25/ghost-cms-cve-2026-26980-clickfix-the-cms-compromise-to-endp · ATT&CK page ↗
Stealth TA0005
T1480Execution Guardrails×1
Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target. Guardrails ensure that a payload only executes against an intended target and reduces collateral damage from an adversary’s campaign. Values an adversary can provide about a target system or environment to use as guardrails may include specific network share names, attached physical devices, files, joined Active Directory (AD) domains, and local/external IP addresses.
Evidence: 2026-05-25/ghost-cms-cve-2026-26980-clickfix-the-cms-compromise-to-endp · ATT&CK page ↗
Credential Access TA0006
T1552Unsecured Credentials×1
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Evidence: 2026-05-25/ghost-cms-cve-2026-26980-clickfix-the-cms-compromise-to-endp · ATT&CK page ↗
Command and Control TA0011
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-05-25/ghost-cms-cve-2026-26980-clickfix-the-cms-compromise-to-endp · ATT&CK page ↗
T1659Content Injection×1
Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic. Rather than luring victims to malicious payloads hosted on a compromised website (i.e., Drive-by Target followed by Drive-by Compromise), adversaries may initially access victims through compromised data-transfer channels where they can manipulate traffic and/or inject their own content. These compromised online network channels may also be used to deliver additional payloads (i.e., Ingress Tool Transfer) and other data to already compromised systems.
Evidence: 2026-05-25/ghost-cms-cve-2026-26980-clickfix-the-cms-compromise-to-endp · ATT&CK page ↗
Entries about Ghost CMS Content API unauthenticated SQLi (CVSS 9.4); ITW-exploited in ClickFix campaign; fixed 6.19.1 (2)
Where this entity is cited
Source distribution
- attack.mitre.org8 (73%)
- bleepingcomputer.com1 (9%)
- blog.xlab.qianxin.com1 (9%)
- github.com1 (9%)
External references
All cited sources (11)
- github.comprimaryGitHub Security Advisory GHSA-w52v-v783-gw97https://github.com/advisories/GHSA-w52v-v783-gw97
- attack.mitre.org`T1059.001`https://attack.mitre.org/techniques/T1059/001/
- attack.mitre.org`T1059.003`https://attack.mitre.org/techniques/T1059/003/
- attack.mitre.org`T1105`https://attack.mitre.org/techniques/T1105/
- attack.mitre.org`T1190`https://attack.mitre.org/techniques/T1190/
- attack.mitre.org`T1204.002`https://attack.mitre.org/techniques/T1204/002/
- attack.mitre.org`T1480`https://attack.mitre.org/techniques/T1480/
- attack.mitre.org`T1552`https://attack.mitre.org/techniques/T1552/
- attack.mitre.org`T1659`https://attack.mitre.org/techniques/T1659/
- bleepingcomputer.comBleepingComputer, 2026-05-24https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/
- blog.xlab.qianxin.comXLab Qianxin, 2026-05-21https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/