Skip to content
September 27, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • Ghost Cache Poisoning Flaw Lets Attackers Hijack Staff Accounts
  • Vulnerability Report

Ghost Cache Poisoning Flaw Lets Attackers Hijack Staff Accounts

Do Son July 8, 2026 2 minutes read
0
Ghost cache poisoning XSS via x-ghost-preview header advisory graphic
Add Daily CyberSecurity as a preferred source on Google
At a glance
  • CVE: CVE-2026-53943
  • CVSS: 9.6 (Critical · CVSSv3)
  • Product: ghost (npm)
  • Affected: >= 4.0.0, <= 6.36.0
  • Impact: Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
  • Status: No confirmed exploitation yet
  • Patched in: 6.37.0
  • EPSS: 0.3% (30-day)
  • Action: Update to 6.37.0 now

Turn matching CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.

Try Team free for 14 days →

Ghost released version 6.37.0 to fix a critical cache poisoning bug. The Ghost cache poisoning flaw, tracked as CVE-2026-53943, scores 9.6 on the CVSS scale. An unauthenticated attacker can abuse it to hijack staff accounts on some setups.

Why This Ghost Cache Poisoning Bug Matters

Ghost powers tens of thousands of sites and serves hundreds of millions of requests each day. Big names like Mozilla, DuckDuckGo, and Cloudflare rely on it. As a result, one shared-cache flaw can reach a huge audience.

The bug needs no login, and the fix already ships. Therefore, exposed sites should update without delay.

How the Attack Works

Many Ghost sites sit behind a shared cache such as Fastly, Cloudflare, or nginx. The cache key, however, ignores the x-ghost-preview header. So the server can store a preview response under the same key as the public page.

An attacker sends a crafted x-ghost-preview header to a normal URL. The poisoned preview output then lands in the shared cache. Later visitors to that page receive the attacker’s injected content instead.

From Cache Poisoning to Account Takeover

When the frontend and admin panel share one domain, the injected script can read session cookies. Consequently, an attacker can hijack staff accounts. Sites that split these onto separate domains avoid this exposure.

Affected Versions

The flaw affects Ghost from v4.0 through v6.36.0. Version 6.37.0 delivers the fix. Additionally, you can check each build on the official Ghost releases page.

Patch and Mitigation

Update to Ghost 6.37.0 or later right away. If you cannot patch yet, set your cache layer to bypass requests carrying the x-ghost-preview header. Suspect a breach? Use the “Reset all authentication” option under Settings, added in v6.41.0. The official GitHub advisory lists the full details.

No public exploit or in-the-wild abuse has been reported. A researcher known as CryptoCat disclosed the issue responsibly. Even so, the high score makes fast action on this Ghost cache poisoning flaw wise.

Related coverage

  • WAGO System I/O Flaw CVE-2026-4769 Leads to Full System Compromise
  • CVE-2026-1603: Remote Unauthenticated Attacker Can Steal Ivanti EPM Secrets
  • High-Severity Node.js Flaws Expose Windows Apps to Path Traversal (CVE-2025-27210) & HashDoS (CVE-2025-27209) Attacks
  • Critical Request Smuggling & Cache Flaws Discovered in Cloudflare’s Pingora
  • Netlogon RCE Vulnerability Under Active Attack in the Wild
  • nopCommerce Flaw (CVE-2025-11699) Allows Admin Takeover by Reusing Session Cookies After Logout
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover Cache Poisoning CVE-2026-53943 ghost Ghost CMS x-ghost-preview XSS

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intel📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intel📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-88771CVSS 9.5
    Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37,...
    📅 Updated: Sep 27, 2026
  • CVE-2026-88772CVSS 9.5
    Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before...
    📅 Updated: Sep 27, 2026
  • CVE-2026-88773CVSS 9.3
    Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This...
    📅 Updated: Sep 27, 2026
  • CVE-2026-100741CVSS 9.8
    Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows,...
    📅 Updated: Sep 27, 2026
  • CVE-2026-96625CVSS 9.1
    fedify-dev/fedify repository advisory GHSA-q9f8-5hc7-898f
    📅 Updated: Sep 27, 2026
  • CVE-2026-94130CVSS 9.3
    Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection...
    📅 Updated: Sep 27, 2026
  • CVE-2026-97161CVSS 9.2
    Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
    📅 Updated: Sep 27, 2026
  • CVE-2026-97163CVSS 10.0
    Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
    📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.