A Critical WHMCS RCE Just Got Patched. Did You Update?

A Critical Whmcs Rce Just Got Patched Did You Update
Follow Us:
2.7k
1k

Key Takeaways

  • WHMCS just patched a critical flaw that could let an attacker take control of an unpatched installation.

  • A second vulnerability could expose customer information through the 2CheckOut payment gateway.

  • If you run WHMCS yourself, it’s time to update and check your installation if you were running a vulnerable version.

Hosting providers have yet another thing to check on their servers: WHMCS just patched a critical remote-code-execution vulnerability affecting versions 8.0 and later.

Tracked as CVE-2026-67399, the flaw could allow an attacker to run their own code on an unpatched installation without logging in, which could give them full control over the installation and its data.

Someone doesn’t even need to log in to WHMCS to take advantage of the flaw; they can send a request to the vulnerable installation and potentially get it to run their own code on the server, which WHMCS says could then give an attacker full control over the installation and its data.

WHMCS patched the flaw in version 9.0.8 and version 8.13.7, both released September 3. The company recommends that affected users update as soon as possible. Unfortunately, that wasn’t the only security issue in the update.

Customer Data Could Also Be Exposed

While the first vulnerability could let someone run code on the server, this one puts customer information at risk. Yup, there are two vulnerabilities to deal with here.

WHMCS also patched CVE-2026-67398, a separate vulnerability tied to its 2CheckOut payment gateway. An attacker could use the flaw to pull personal information from WHMCS customers, including names, addresses, email addresses, phone numbers, and location details.

Vulnerability What it can expose Timeline
CVE-2026-67399 Remote code execution → potential control of WHMCS/server September 3, 2026: WHMCS released versions 9.0.8 and 8.13.7 with the security fix.
CVE-2026-67398 Customer information → names, addresses, emails, phone numbers, and location details September 3, 2026: WHMCS released the security fix. Affected 8.x installations should update to 8.13.7; affected 9.x installations should update to 9.0.8.

The 67398 advisory says the vulnerability was identified in WHMCS 4.5.0 and later when the affected 2CheckOut module is being used. But the security fix is only available for supported WHMCS versions, so installations running 8.x builds before 8.13.7 need to update to 8.13.7, while 9.x builds before 9.0.8 need to update to 9.0.8.

WHMCS recommends updating to a patched version. If an administrator can’t update right away, the company says the 2CheckOut module can be temporarily disabled.

What Happens If Someone Gets Into WHMCS?

WHMCS can be connected to a lot of the things a hosting provider uses every day — it can handle payments, domains, customer accounts, and service provisioning. Depending on how it’s set up, it may also have access to other systems and credentials.

Someone who compromises WHMCS doesn’t automatically gets access to all of that, but it does mean there are a lot more crevices to check than just checking whether the WHMCS installation itself was compromised.

As for what an attacker could reach from that server? That’s going to look different for every provider, which is why there’s no single answer here. WHMCS says it isn’t aware of either vulnerability being exploited, though.

Self-Hosted Providers Have to Check Their Own Installations

Not every WHMCS customer has to manually install these updates, though: WHMCS says its Cloud installations are updated automatically.

However, self-hosted installations are on their own. For affected installations, that means updating to:

  • WHMCS 8.13.7 or later
  • WHMCS 9.0.8 or later

Providers using the 2CheckOut module should also check whether they’re affected by CVE-2026-67398.

And if an installation was running a vulnerable version, this is a good time to look for anything that doesn’t belong there. Check the logs, look for unexpected changes, and review any credentials or connections that WHMCS could access.

It’s always worth knowing what your WHMCS installation can actually access.