WHMCS has addressed two significant security vulnerabilities in its widely used billing and automation software, including a critical unauthenticated remote code execution (RCE) flaw. The updates, released earlier this month, affect installations running versions 8.0 and later, with no patch available for older branches within the 8.x series outside of upgrading to a supported release.
What was fixed
The primary vulnerability, tracked as CVE-2026-67399, allows attackers to execute arbitrary code on vulnerable WHMCS servers without requiring authentication. The flaw impacts all versions from 8.0 onward, with fixes delivered in WHMCS 9.0.8 and 8.13.7. Administrators running versions 8.0 through 8.12 must upgrade to at least 8.13.7 or migrate to the 9.x branch, as no security updates will be provided for those intermediate releases.
Alongside the RCE flaw, WHMCS resolved CVE-2026-67398, a missing-authorization vulnerability in the bundled 2CheckOut payment gateway module. This issue, disclosed by a researcher identified as "boomerang," enables unauthenticated users to access customer personal data, including names, addresses, contact details, and payment information. The vulnerability affects installations running WHMCS 4.5.0 or later and carries a CVSS 4.0 score of 8.2, classified as High severity.
- CVE-2026-67399: Critical RCE, unauthenticated, affects WHMCS 8.0+
- CVE-2026-67398: High-severity data exposure in 2CheckOut module, affects WHMCS 4.5.0+
- Fixes released in WHMCS 9.0.8 and 8.13.7 on 3 September 2026
- No in-branch fix for WHMCS 8.0–8.12; upgrade required
- Temporary workaround for 2CheckOut flaw: deactivate module and switch gateways
Why the vulnerabilities matter
WHMCS serves as a central hub for many hosting providers, managing customer accounts, billing, and automated service provisioning. The platform integrates with control panels like cPanel, Plesk, and DirectAdmin, as well as domain registrars and payment processors. These integrations often involve storing API credentials and other sensitive configuration data, which could be exposed if an attacker successfully exploits the RCE vulnerability.
While WHMCS has not reported any confirmed exploitation of CVE-2026-67399 in the wild, the public disclosure of the flaw increases the risk of attack. Security researchers note that once a vulnerability is made public, attackers can analyze the differences between patched and unpatched versions to develop exploits. The timing of this disclosure, less than a month after a separate authentication vulnerability in cPanel (CVE-2026-41940), underscores the importance of promptly patching core hosting infrastructure.
Steps for administrators
WHMCS administrators should prioritize upgrading to a patched version. The process involves:
- Version check: Log into the WHMCS admin area and navigate to Utilities → Update WHMCS to confirm the installed version.
- Upgrade path: Install WHMCS 9.0.8 or 8.13.7. Those running versions 8.0–8.12 must upgrade to a newer release, as no security fixes will be backported to those branches.
- Testing: If the installation includes custom modules, hooks, or third-party integrations, test the upgrade in a staging environment first to avoid compatibility issues.
- Mitigation for 2CheckOut users: If immediate upgrading is not possible, deactivate the 2CheckOut module and switch to an alternative payment gateway. This step only addresses the data-exposure flaw, not the RCE vulnerability.
- Post-upgrade review: After applying the update, examine server and WHMCS access logs for unusual activity. Rotate API keys, passwords, and integration credentials if any indicators of compromise are detected.
For professionals: Hosting providers relying on WHMCS for billing and automation should treat this update as urgent. The RCE flaw could allow attackers to compromise not only customer data but also credentials used to connect WHMCS to other critical systems. Delaying patching increases exposure to potential exploitation, particularly as details of the vulnerability become more widely known.
Automated pipeline · Security
Synthesized from 1 industry feed on 10 Sep 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story WHMCS RCE vulnerability not previously covered in context.
- Writing the article — Draft created article_id=540 slug=whmcs-patches-critical-rce-flaw-in-billing-platform
-
Editor review — Approved
- Score: 95/100
- Factual grounding: The draft states the fixes were released 'earlier this month' without specifying the date, while the source explicitly states the advisory was published on 3 September 2026. The Key facts block correctly includes the date, but the prose should align with the source's precision.
- Style compliance: The standfirst uses 'update required' which is slightly directive. While not material, a more neutral phrasing like 'update available' would better match the trade-press tone.
- No copied phrasing: The phrase 'missing-authorization vulnerability in the bundled 2CheckOut payment gateway module' closely mirrors the source's 'missing-authorization vulnerability (CWE-862) in WHMCS’s bundled 2CheckOut payment gateway module'. While the fact is correct, the phrasing should be restructured further to avoid echoing the source.
- Generating reader Q&A — Generated 4 items
- Assigning hero image — Reused library image reused image #19
- Linking related stories — Linked 4 relations from 470 candidates
- Publishing — Published whmcs-patches-critical-rce-flaw-in-billing-platform
- Mastodon — Posted https://mstdn.social/@hostingpaper/117247546572204054




Discussion · coming soon
Be the first to join the thread when community discussion launches.