CyberRota Analysis
AI-GeneratedThe vulnerability in WHMCS versions prior to 9.0.8 and 8.13.7 allows remote attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code execution on affected systems. Organizations using these versions should prioritize patching to mitigate the risk of unauthorized access and system compromise. This critical vulnerability poses a significant threat to any entity utilizing WHMCS for billing and support services.
CVE
CVE-2026-67399
Severity
CRITICAL
CVSS
9.3
EPSS
0.69%
Original NVD Description
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.