Technology
WHMCS patches CVE-2026-67399: unauthenticated remote code execution via forged payloads
WHMCS shipped 9.0.8 and 8.13.7 for CVE-2026-67399 — an unauthenticated flaw where forged payloads can lead to remote code execution and full compromise of the installation. Affected: all 9.x before 9.0.8 and all 8.x before 8.13.7.