WHMCS released maintenance updates resolving two critical WHMCS vulnerabilities on September 3, 2026. The flaws allow unauthenticated remote attackers to execute arbitrary code and harvest sensitive client details. Administrators should apply the released updates immediately to protect their web hosting operations.
- Product: WebPros WHMCS
- Vulnerabilities: 2 flaws (CVE-2026-67399, CVE-2026-67398)
- Highest severity: 9.3 (Critical · CVSSv4)
- Worst impact: Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows...
- Status: No confirmed exploitation yet; patches available
- Action: Update to 9.0.8, 8.13.7, 8.12.2 now
| CVE | CVSS (CVSSv4) | Fixed in | Status |
|---|---|---|---|
| CVE-2026-67399 | 9.3 | 9.0.8, 8.13.7 | Not exploited |
| CVE-2026-67398 | 8.2 | 8.12.2, 8.13.7, 9.0.8 | Not exploited |
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy This Threat Matters
Industry estimates indicate that tens of thousands of web hosting providers use WHMCS to manage billing and server provisioning. Therefore, vulnerabilities within this core platform threaten client records and cloud infrastructure worldwide. If an attacker breaches the billing system, they can disrupt hosting services and access stored payment records. Furthermore, criminals can abuse customer data to launch secondary phishing campaigns against end users.
How the Attacks Work
The updates resolve two distinct security weaknesses. The primary flaw, CVE-2026-67399, carries a critical CVSS score of 9.3. The official bulletin states, “A security vulnerability (CVE-2026-67399) has been identified in WHMCS 8.0.x and later involving the submission of forged payloads without adequate restrictions.” An unauthenticated attacker sends crafted network requests to execute code on the host server.
Meanwhile, CVE-2026-67398 affects the 2CheckOut payment gateway module. The advisory explains that an unauthenticated user could “retrieve personally identifiable information (PII) for a client, including the client’s name, address, city, state, postal code, country, email, and phone number.” Attackers query the payment handler to access private customer directories. Currently, researchers have confirmed no active in-the-wild exploitation. Likewise, no public proof-of-concept exploit code exists.
Affected Versions
These WHMCS vulnerabilities impact all WHMCS 9.x installations prior to 9.0.8. They also affect WHMCS 8.x releases prior to 8.13.7.
Patch and Mitigation Steps
Administrators must update their installations to versions 9.0.8 or 8.13.7 immediately. If administrators cannot update immediately, they should deactivate the 2CheckOut payment module within payment gateway settings.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!