Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-67399: WHMCS lets attackers run code remotely

CVE-2026-67399 · published 7 days ago
Summary

Versions of WHMCS prior to 9.0.8 and 8.13.7 can be tricked into loading malicious data, which may let an outsider execute commands on your server. This could lead to data theft, service disruption, or full system takeover. Upgrade WHMCS to the latest release or apply the vendor's security patch as soon as possible.

What to do
  • Update webpros whmcs to version 9.0.8 or later.
Affected software
VendorProductAffected versions
webpros whmcs < 9.0.8
Original advisory text
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
Severity
9.3 Critical
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published14 Sep 2026
Updated21 Sep 2026
First seen14 Sep 2026
Sources
CVE-2026-67399 · MITRE
Track software like this
Free during beta