SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-67399

CRITICAL · CVSS 9.3 EPSS 0.69%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in WHMCS versions prior to 9.0.8 and 8.13.7 allows remote attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code execution on affected systems. Organizations using these versions should prioritize patching to mitigate the risk of unauthorized access and system compromise. This critical vulnerability poses a significant threat to any entity utilizing WHMCS for billing and support services.

CVE
CVE-2026-67399
Severity
CRITICAL
CVSS
9.3
EPSS
0.69%

Original NVD Description

Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.