← Back to Vulnerability Reports CVE Intelligence

CVE-2026-26980

GhostCRITICAL · CVSS 9.4 In the wild

What is CVE-2026-26980?

Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.

CVSS9.4 NVD 3.1
SeverityCRITICAL
Exploitation In the wild
Triage statusActive Exploit
ActionPatch within 48 hours
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
NVD published2026-02-20
NVD last modified2026-05-26

Affected product

Ghost

Remediation Steps

  1. Apply the latest Ghost CMS security update that addresses the SQL injection vulnerability
  2. Audit Ghost instances for injected malicious JavaScript in content
  3. Review user activity logs for signs of compromise or unauthorized modifications
  4. Implement Content Security Policy (CSP) headers to mitigate JavaScript injection impact
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.