• Vineri, Septembrie 4, 2026

We would like to bring your attention to two important security updates affecting WHMCS and ConfigServer Firewall (CSF).

If you operate either product, we strongly recommend reviewing your installed version and applying the available updates as soon as possible.


1. WHMCS Security Update : 9.0.8 and 8.13.7

WHMCS has released version 9.0.8 and 8.13.7 to address two security vulnerabilities identified through its internal security review process.

WHMCS has stated that it is not aware of any exploitation of these vulnerabilities at this time.

CVE-2026-67398 : Customer Data Disclosure via 2Checkout

Under specific conditions, an unauthenticated user could potentially access customer information through the 2Checkout payment gateway integration.

Potential impact:

  • Enumeration of invoice IDs
  • Exposure of customer information such as name, address, email address, phone number and related data

Affected versions:

  • WHMCS 9.x versions prior to 9.0.8
  • WHMCS 8.x versions prior to 8.13.7
  • WHMCS 4.5 and later are affected by the underlying issue and require upgrading to a supported patched release

Patched versions:

  • WHMCS 9.0.8
  • WHMCS 8.13.7

Official advisory:
https://help.whmcs.com/m/125386/l/2116695-cve-2026-67398-whmcs-security-update-2026-09-03


CVE-2026-67399 : Unauthenticated Remote Code Execution

A second vulnerability could allow an unauthenticated attacker, under specific conditions, to submit a forged payload that is deserialized without adequate restrictions.

Successful exploitation could result in arbitrary code execution on the WHMCS server, potentially leading to full compromise of the WHMCS installation and its data.

Affected versions:

  • WHMCS 9.x versions prior to 9.0.8
  • WHMCS 8.x versions prior to 8.13.7

Patched versions:

  • WHMCS 9.0.8
  • WHMCS 8.13.7

Official advisory:
https://help.whmcs.com/m/125386/l/2118034-cve-2026-67399-whmcs-security-update-2026-09-03

Recommended Action for WHMCS Users

If you operate a self-managed WHMCS installation:

  1. Take a full backup of your WHMCS installation and database.
  2. Log in to your WHMCS Admin Area.
  3. Navigate to Utilities > Update WHMCS.
  4. Update to:
    • WHMCS 9.0.8 if you are using the 9.0.x release series
    • WHMCS 8.13.7 if you are using the 8.13.x release series
  5. Verify the installed version after the update.

If you use the 2Checkout payment gateway and cannot update immediately, WHMCS recommends temporarily deactivating the gateway until the update can be applied.

For CVE-2026-67399, there is no customer-side workaround. Updating WHMCS is the required remediation.

If you updated WHMCS recently, please check again. These releases follow closely after earlier maintenance updates, so a recently updated installation may still require this latest security release.


2. ConfigServer Firewall (CSF) Security Update : CVE-2026-67402

A security vulnerability has also been identified in ConfigServer Firewall (CSF) involving its Messenger service.

CVE-2026-67402 : CSF Messenger Service Code Execution

An unauthenticated attacker may be able to exploit the CSF Messenger service to execute code on the server.

Potential impact:

Successful exploitation could allow code execution under the Apache user and increase an attacker's level of access to the server.

Affected versions:

  • ConfigServer Firewall (CSF) 16.30-1 and older

Patched version:

  • ConfigServer Firewall (CSF) 16.31 or later

Recommended Action for CSF Users

Servers configured for automatic updates should receive the patched version automatically.

To apply the update immediately, log in to the server as root and run:

yum clean all
/scripts/update-packages

After updating, verify that your server is running CSF 16.31 or later.

If your server is running an end-of-life version of cPanel & WHM, we strongly recommend upgrading to a supported version so that you can continue receiving current security and package updates.


Keep Your Hosting Stack Current

Security maintenance is an ongoing part of operating hosting infrastructure.

Even if a system was updated recently, new security releases may require another version check shortly afterwards.

We recommend that customers regularly:

  • Review installed software versions
  • Apply vendor security updates promptly
  • Maintain tested backups before upgrades
  • Confirm that automatic update mechanisms are working
  • Upgrade end-of-life software to supported versions

Keeping core systems such as WHMCS, control panels, firewalls and server software current remains one of the most important steps in maintaining a secure hosting environment.