securityonline.info 9/4/2026, 2:23:52 AM · external

Critical WHMCS Security Update Patches RCE Flaws

Critical WHMCS Security Update Patches RCE Flaws
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

SUMMARY of critical vulnerabilities and updates affecting WHMCS billing platforms. There are notable issues including a remote code execution flaw (CVE-2026-67399) that allows an attacker to control the hosting environment, and a data exposure flaw (CVE-2026-67398) leaking client information. Both vulnerabilities impact various versions of WHMCS, with recommended updates provided to mitigate these risks. Users are urged to apply security patches immediately to protect their systems.

View full article

Article by CyberSIXT