Image: WHMCS
Two critical vulnerabilities impact WHMCS billing platforms. A new WHMCS security update resolves a severe remote code execution flaw and a customer data disclosure bug. The vendor confirms no public exploits currently exist.
Why It Matters
These flaws threaten web hosting infrastructure globally. First, the remote code execution flaw allows complete system takeover. Consequently, attackers can control the entire hosting environment and modify billing data. Next, the secondary flaw exposes sensitive client records. This exposes names, addresses, and contact details to unauthorized actors.
How the Attack Works
The primary flaw, CVE-2026-67399, centers on input validation failures. Attackers submit forged payloads into the system. As stated in the security advisory, this issue involves “the submission of forged payloads without adequate restrictions.” Under specific conditions, this leads directly to arbitrary code execution.
Meanwhile, CVE-2026-67398 resides in the 2CheckOut payment gateway module. Unauthenticated users manipulate module inputs to retrieve personally identifiable information. Specifically, this exposes the client’s name, address, email, and phone number.
Affected Versions
These bugs impact multiple software branches. CVE-2026-67399 affects all WHMCS 8.0.x versions and newer. Similarly, CVE-2026-67398 affects versions from 4.5.0 onward. Both vulnerabilities impact all WHMCS 9.x builds prior to 9.0.8 and 8.x builds prior to 8.13.7.
Patch and Mitigation Steps
Administrators must apply the WHMCS security update immediately. The vendor released WHMCS 9.0.8 and 8.13.7 to fix both issues. Read the official CVE-2026-67399 advisory for RCE details. Also, review the CVE-2026-67398 advisory for the data leak fix. As a temporary workaround for the data leak, administrators can deactivate the 2CheckOut payment gateway module in system configuration settings.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!