https://reddit.com/r/cybersecurity/comments/1tnoc8h/ghost_cms_flaw_being_actively_exploited_to/: Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February
Published May 25, 2026
·Updated
Affected Software
1 affected component
Ghost Ghost CMS<6.19.1
Frequently Asked Questions
1
What is the severity of CVE-2026-26980?
CVE-2026-26980 has a severity score of 9.4 according to CVSS, indicating a critical vulnerability.
2
How do I fix CVE-2026-26980?
To fix CVE-2026-26980, update your Ghost CMS to version 6.19.1 or later.
3
What type of vulnerability is CVE-2026-26980?
CVE-2026-26980 is classified as a critical SQL injection flaw.
4
How long has CVE-2026-26980 been actively exploited?
CVE-2026-26980 has been actively exploited since May 7, 2026.
5
Which software is affected by CVE-2026-26980?
CVE-2026-26980 affects the Ghost CMS software.