Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-43642: Virtualizor permits remote code execution through billing module
CVE-2026-43642 · published 5 days ago
Summary
The Virtualizor control panel (versions before 3.2.9 and 3.0.0) lets anyone on the internet send specially crafted data to its billing feature, causing the server to run whatever code the attacker includes. This can give the attacker full control of the server. Update Virtualizor to the latest patched version or apply the official security update as soon as possible.
What to do
- Update softaculous virtualizor to version 3.2.9 (Patch 9) or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| softaculous | virtualizor | < 3.2.9 (Patch 9) |
Original advisory text
Softaculous Virtualizor PHP Object Injection via Billing Module Handler
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects for deserialization by setting the act parameter to login with the from_billing_module parameter present. Attackers can pass malicious serialized data through the billing_data POST field to the unserialize() function without allowed_classes restrictions, enabling exploitation of available POP chains to achieve remote code execution as root.
References
- https://www.vulncheck.com/blog/virtualizor-billing-hook-unauthenticated-root-rce technical-description exploit
- https://www.virtualizor.com/blog/virtualizor-3-2-9-launched-release-candidate-pa... release-notes patch
- https://www.virtualizor.com/blog/virtualizor-3-3-0/ release-notes patch
- https://www.vulncheck.com/advisories/softaculous-virtualizor-php-object-injectio... third-party-advisory
Severity
9.2
Critical
CVSS 3.1: 8.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published22 Sep 2026
Updated27 Sep 2026
First seen22 Sep 2026
Track software like this
Free during beta