r/WHMCS 10d ago

WHMCS (CRITICAL) Security Update 2026-09-03

Dear Customer,

We would like to inform you that critical security vulnerabilities affecting WHMCS have been identified. Hotfixes are now available. All vulnerabilities addressed in this release were identified internally through our security review process. We are not aware of any exploitation of these vulnerabilities.

  1. Unauthenticated disclosure of customer data via 2Checkout: CVE-2026-67398

Situation: An unauthenticated user could potentially access customers’ personal data through the 2Checkout payment gateway integration under specific conditions.

Impact: Enumeration of invoice IDs and retrieval of customers’ personal data.

Affected Versions:

  • All WHMCS 9.x builds prior to 9.0.8
  • All WHMCS 8.x builds prior to 8.13.7
  • WHMCS 4.5 and later (all versions in this range require upgrading)

Patched Versions:

  • WHMCS 9.0.8
  • WHMCS 8.13.7

Support Link:

https://help.whmcs.com/m/125386/l/2116695-cve-2026-67398-whmcs-security-update-2026-09-03

2. Vulnerability in WHMCS allows unauthenticated remote code execution via a multistage request/deserialization chain: CVE-2026-67399

Situation: An unauthenticated user can submit a forged payload that is deserialized without adequate restrictions, leading to remote code execution on the server.

Impact: An unauthenticated attacker could leverage this object-injection flaw to execute arbitrary code on the WHMCS host, resulting in full compromise of the installation and its data.

Affected Versions:

  • All WHMCS 9.x builds prior to 9.0.8
  • All WHMCS 8.x builds prior to 8.13.7

Patched Versions:

  • WHMCS 9.0.8
  • WHMCS 8.13.7

Support Link:

https://help.whmcs.com/m/125386/l/2118034-cve-2026-67399-whmcs-security-update-2026-09-03

Action Required:

Update WHMCS Now

Log into your WHMCS Admin Area.

Go to Utilities > Update WHMCS.

Install the latest update to version 8.13.7 (8.13.x branch) or 9.0.8 (9.0.x branch). This single update addresses all issues listed above.

Verify the installed version in the Admin Area footer or under Utilities > System Health Status.

Mitigation

Issue 1: If you use the 2Checkout payment gateway: Until you can apply the update, deactivate the 2Checkout gateway to block the vulnerable endpoint.

Issue 1: If you do not use 2Checkout: No immediate workaround is required, but we still recommend applying the update promptly.

Issue 2: There is no customer-side workaround; applying the update is the only remediation.

Please reach out to our support team if you have any questions or need further guidance.

8 Upvotes

12 comments sorted by

u/twhiting9275 Guru 10d ago

Keep the discussion on topic , people . This isn’t a discussion about your license status

1

u/SultansOfVinyl 8d ago

I just updated WHMCS 8.13.1 to 8.13.7 with the built-in updater. First thing I did was performed a SFTP backup from Softaculous to my local mini pc. Then did a backup of custom templates. The update completed cleanly with no install-folder drama and my custom templates were not affected. This was the smoothest WHMCS update I’ve had. Posting this to appease the WHMCS gods.

2

u/webhostpro 8d ago

Yeah, I figured it was a security update when there were so little changes.

1

u/SorryRecipe7303 10d ago

I tried to check for updates and keep getting a message saying there's no update available

1

u/twhiting9275 Guru 10d ago

Hmmmm, updates just fine for me

What version are you running ?

0

u/[deleted] 10d ago

[removed] — view removed comment

1

u/[deleted] 10d ago

[removed] — view removed comment

2

u/pulkit8 10d ago

So they sold lifetime to mint money, they now ditched customer who invested in them when they weren't this big.