CVE-2026-26980
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
- Published Feb 20, 2026
- CVSS 7.5 high
- 5.0% chance of exploitation in the next 30 days (EPSS)
- Public exploit code is available
- A fix is available
Affected software
In the news
- VulnCheck State of Exploitation 1H-2026 VulnCheck Blog ·
- Observations on Anthropic’s Vulnerability Disclosure Ledger VulnCheck Blog ·