CVE-2026-67399: WebPros Whmcs

Critical severity, CVSS 9.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.

Affected products

  • WebPros Whmcs: from 9.0.0, before 9.0.8 (fixed in 9.0.8); from 8.0.0, before 8.13.7 (fixed in 8.13.7)

Published 2026-09-14. Last modified 2026-09-18.