WHMCS Has an Unauthenticated RCE. The Fix Exists Only for 9.0.8 and 8.13.7.

WHMCS published two security advisories on September 3. The more serious, CVE-2026-67399, lets an unauthenticated attacker submit forged payloads and, under conditions the vendor does not spell out, execute arbitrary code on the WHMCS host. The advisory says this could result in full compromise of the installation and its data, and that the vulnerable code has been … Continue reading WHMCS Has an Unauthenticated RCE. The Fix Exists Only for 9.0.8 and 8.13.7.