CVE-2026-67399: WHMCS WHMCS vulnerability
Published Sep 14, 2026
·Updated
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
Affected Software
2 affected components
WHMCS WHMCS>9.0.0<9.0.8
WHMCS WHMCS>8.0.0<8.13.7
Event History
Sep 14, 2026
CVE Published
via MITRE·08:53 PM
Data Sourced
via MITRE·08:53 PM
DescriptionWeakness
Frequently Asked Questions
1
Which WHMCS versions need to be remediated?
WHMCS 9.0.0 through versions before 9.0.8 are affected, as are WHMCS 8.0.0 through versions before 8.13.7. Upgrade to 9.0.8 or later on the 9.x branch, or 8.13.7 or later on the 8.x branch.
2
What level of access does an attacker need?
The issue is described as remotely exploitable and can allow arbitrary code execution. The provided information does not state that authentication or prior access is required.