CVE-2026-67399
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
| CWE | CWE-502 |
| Vendor | webpros |
| Product | whmcs |
| Published | Sep 14, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for webpros whmcs
Be the first to know when new unknown vulnerabilities affecting webpros whmcs are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WebPros / WHMCS
9.0.0 < 9.0.8 8.0.0 < 8.13.7
References
Credits
๐ azizk (@realazizk)