A Critical WHMCS RCE Just Got Patched. Did You Update?

Writer: Jordan Sprogis

Editor: Lillian Castro

Reviewer: Cristian Lopez

Follow the HostingAdvice team for a daily dose of tech news, trending IT discussions, and interviews with the web's most innovative technologists.
Follow Us:
2.7k
1k

Key Takeaways

  • WHMCS just patched a critical flaw that could let an attacker take control of an unpatched installation.

  • A second vulnerability could expose customer information through the 2CheckOut payment gateway.

  • If you run WHMCS yourself, it’s time to update and check your installation if you were running a vulnerable version.

Hosting providers have yet another thing to check on their servers: WHMCS just patched a critical remote-code-execution vulnerability affecting versions 8.0 and later.

Tracked as CVE-2026-67399, the flaw could allow an attacker to run their own code on an unpatched installation without logging in, which could give them full control over the installation and its data.

Someone doesn’t even need to log in to WHMCS to take advantage of the flaw; they can send a request to the vulnerable installation and potentially get it to run their own code on the server, which WHMCS says could then give an attacker full control over the installation and its data.

WHMCS patched the flaw in version 9.0.8 and version 8.13.7, both released September 3. The company recommends that affected users update as soon as possible. Unfortunately, that wasn’t the only security issue in the update.

Customer Data Could Also Be Exposed

While the first vulnerability could let someone run code on the server, this one puts customer information at risk. Yup, there are two vulnerabilities to deal with here.

WHMCS also patched CVE-2026-67398, a separate vulnerability tied to its 2CheckOut payment gateway. An attacker could use the flaw to pull personal information from WHMCS customers, including names, addresses, email addresses, phone numbers, and location details.

Vulnerability What it can expose Timeline
CVE-2026-67399 Remote code execution → potential control of WHMCS/server September 3, 2026: WHMCS released versions 9.0.8 and 8.13.7 with the security fix.
CVE-2026-67398 Customer information → names, addresses, emails, phone numbers, and location details September 3, 2026: WHMCS released the security fix. Affected 8.x installations should update to 8.13.7; affected 9.x installations should update to 9.0.8.

The 67398 advisory says the vulnerability was identified in WHMCS 4.5.0 and later when the affected 2CheckOut module is being used. But the security fix is only available for supported WHMCS versions, so installations running 8.x builds before 8.13.7 need to update to 8.13.7, while 9.x builds before 9.0.8 need to update to 9.0.8.

WHMCS recommends updating to a patched version. If an administrator can’t update right away, the company says the 2CheckOut module can be temporarily disabled.

What Happens If Someone Gets Into WHMCS?

WHMCS can be connected to a lot of the things a hosting provider uses every day — it can handle payments, domains, customer accounts, and service provisioning. Depending on how it’s set up, it may also have access to other systems and credentials.

Someone who compromises WHMCS doesn’t automatically gets access to all of that, but it does mean there are a lot more crevices to check than just checking whether the WHMCS installation itself was compromised.

As for what an attacker could reach from that server? That’s going to look different for every provider, which is why there’s no single answer here. WHMCS says it isn’t aware of either vulnerability being exploited, though.

Self-Hosted Providers Have to Check Their Own Installations

Not every WHMCS customer has to manually install these updates, though: WHMCS says its Cloud installations are updated automatically.

However, self-hosted installations are on their own. For affected installations, that means updating to:

Providers using the 2CheckOut module should also check whether they’re affected by CVE-2026-67398.

And if an installation was running a vulnerable version, this is a good time to look for anything that doesn’t belong there. Check the logs, look for unexpected changes, and review any credentials or connections that WHMCS could access.

It’s always worth knowing what your WHMCS installation can actually access.

About the Author

Contributing Expert

Jordan Sprogis is a creative writer and tech researcher who has been working on online content for the better part of a decade. She holds a bachelor's degree in professional writing from Western Connecticut State University and has devoted much of her career to crafting content for various web verticals, including CyberSpyder and The Echo. Since joining HostingAdvice, Jordan has combined her storytelling ability with her fascination for advancements in technology to pen over 500 articles geared toward industry pros and newcomers alike.

« BACK TO: BLOG

Meet the Experts

Our team of experts with a combined 50+ years of experience in web hosting serve insight and advice to more than 20 million users!

We Know Hosting

$

4

8

,

2

8

3

spent annually on web hosting!