CVE-2026-26980: Ghost is a Node.js content management system. Versions
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
- EPSS 70.2% (99.3% percentile)
- CVSS 9.4 critical
Related briefings
- New Rust backdoor takes its orders from GitHub 2026-08-17
- Fake fix prompts spread ACR Stealer to raid corporate browser logins 2026-07-17
- Hackers hijack Mexican bank customers with a hands-on fraud toolkit 2026-07-08
- Microsoft 365 account-hijack kit spreads on a Russian cybercrime forum 2026-06-30
- Hackers use AI to fake a bank site and seize victims' PCs 2026-06-18