CVE

CVE-2026-26980

Ghost has a SQL Injection in its Content API

Exploitation IoCs 3

Domain corepack[.]org
Filename lib/.threadpool.rb
IP 165[.]154[.]236[.]93

MITRE ATT&CK TTPs 13

Source Articles