Security NEXT•September 15, 2026•🇯🇵Translated from Japanese

Critical Vulnerabilities Patched in WHMCS Billing Software for Hosting Providers

WebPros International has disclosed two serious vulnerabilities in its WHMCS billing management platform used by hosting and cloud service providers.

The first flaw, tracked as CVE-2026-67399, is caused by unsafe deserialization of untrusted data. Under specific conditions, it permits unauthenticated attackers to execute arbitrary code on the server, which could lead to full compromise of the installation and related customer data.

The second issue, CVE-2026-67398, affects the 2CheckOut payment gateway module. It results from missing authorization controls and allows unauthenticated access to personal customer details such as names, addresses, email addresses, and telephone numbers.

HackerOne rated CVE-2026-67399 with a CVSS v4.0 base score of 9.3 (Critical) and CVE-2026-67398 with a score of 8.2 (High).

WebPros has released patched versions WHMCS 9.0.8 and 8.13.7 that address both vulnerabilities. Administrators are urged to apply the updates immediately. For CVE-2026-67398, the company also advises temporarily disabling the 2CheckOut module as a workaround until the patch is installed.

Related articles

Hispasec•Vulnerabilities & Exploits

Critical CVE-2026-61500 in Rejetto HFS Allows Admin Session Forgery Leading to Remote Code Execution

A critical vulnerability tracked as CVE-2026-61500 is being actively exploited in Rejetto HTTP File Server (HFS), enabling unauthenticated attackers to forge administrator sessions and achieve remote code execution. The flaw impacts versions 3.0.0 through 3.2.0 and was addressed in release 3.2.1, making immediate updates essential for any internet-exposed instances. The root cause lies in the use of JavaScript Math.random() to generate the session cookie signing key instead of a cryptographically secure random number generator. Attackers can reconstruct the internal state of this weak PRNG from login responses, allowing them to create valid admin cookies. Once authenticated as an administrator, the attacker can abuse the server_code functionality to execute arbitrary JavaScript on the server. Exploitation activity was first observed on October 1, 2026, targeting U.S. systems and attributed to an unidentified actor based in China, following the public release of a Python proof-of-concept in late September.

BoletimSec•Vulnerabilities & Exploits

Dell Patches Six Critical Flaws in Container Storage Modules for Kubernetes

Dell has fixed six vulnerabilities in its Container Storage Modules that integrate storage systems with Kubernetes clusters. Two of the issues received the maximum CVSS score of 10.0, allowing remote unauthenticated attackers to obtain full administrative credentials for registered storage backends. Additional flaws enable privilege escalation to root on cluster nodes, exposure of hardcoded credentials, and leakage of Kubernetes secrets across the entire cluster. All versions prior to 1.17.0 are affected, with the fixes delivered in version 1.18.0. No workarounds exist, and Dell recommends rotating JWT signing keys after applying the update because the previous keys must be considered compromised.

Security NEXT•Vulnerabilities & Exploits

Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution

GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.

Security NEXT•Vulnerabilities & Exploits

WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM

WebPros International has published security updates addressing three critical vulnerabilities in its cPanel & WHM hosting management platform. All three issues received the highest severity rating of Critical. The flaws include CVE-2026-93698, an input validation weakness in the Multilang adminbin component that could allow root-level operating system command execution. Two additional stored cross-site scripting vulnerabilities were also fixed, one of which is CVE-2026-93697 affecting the Mass Modify Accounts interface in WHM. Successful exploitation of the XSS flaws could let low-privileged accounts hijack administrator sessions. The updates were made available on September 29, 2026, and carry CVSS v3.0 base scores reaching 9.9.