WHMCS released maintenance updates on 3 September 2026 to address two vulnerabilities affecting its web-hosting billing and provisioning platform. CVE-2026-67399 is rated critical, with a CVSS v4 score of 9.3, and involves forged payloads being submitted without adequate restrictions. According to the cited advisory, an unauthenticated attacker could send crafted network requests and execute arbitrary code on the host server. The flaw affects WHMCS 8.0.x and later.
CVE-2026-67398, rated 8.2, affects the 2CheckOut payment gateway module. An unauthenticated user could query the payment handler to retrieve client personally identifiable information, including names, addresses, email addresses and telephone numbers. The report says there is no confirmed exploitation in the wild and no publicly available proof-of-concept code.
WHMCS administrators should update to version 9.0.8 or 8.13.7; CVE-2026-67398 is also fixed in 8.12.2. The report states that 9.x installations before 9.0.8 and 8.x installations before 8.13.7 are affected. Where an immediate update is not possible, administrators are advised to disable the 2CheckOut payment module in the payment gateway settings.