Page 1 of 1

CVE-2026-67399 - WHMCS Deserialization of Untrusted Data Remote Code Execution

Posted: Mon Sep 14, 2026 11:40 pm
by Starburst-David
CVE ID :CVE-2026-67399
Published : Sept. 14, 2026, 9:17 p.m. | 44 minutes ago
Description :Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
Severity: 9.3 | CRITICAL

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-67399