CVE-2026-67399EPSS p53.4%

CVE-2026-67399CVE-2026-67399

Description

Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.

Scoring

EPSS0.75% probability of exploitation · percentile 53.4% · 2026-10-05T12:00:23Z
Last modified2026-09-18
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.