WHMCS 9.0.8 and WHMCS 8.13.7 are now available as maintenance releases for the 9.0 and 8.13 series.
Both releases resolve security issues that have been assigned public CVE identifiers, which makes this one worth acting on right away instead of waiting for a convenient moment.
Maintenance and Security Updates
WHMCS 9.0.8 and WHMCS 8.13.7 resolve two security issues, which have been assigned CVE-2026-67399 and CVE-2026-67398.
As is our standard practice, we aren't sharing further technical detail on these issues beyond what's necessary to protect installations that haven't yet updated.
WHMCS 9.0.8 also includes a small number of additional module updates specific to the 9.0 series. Full details for both release series are available in the linked changelogs below.
Because these fixes address named, publicly tracked vulnerabilities, we'd strongly encourage updating without delay.
Updating Your WHMCS Installation
To update, open
Utilities >
Update WHMCS in your admin area and run the Automatic Updater. This is the fastest path for most installations.
Prefer a manual process? Full release packages and incremental patch files are posted on the WHMCS
download page for anyone who'd rather manage the update themselves.
Either way, back up your files and database in full before you start.
Staying Current
Keeping pace with maintenance releases is one of the simplest things you can do to keep a WHMCS installation running securely.
Given what this particular release addresses, we'd ask that everyone on the 9.0 or 8.13 series apply it soon rather than wait for a routine cycle.
Thank you for continuing to run WHMCS, and for keeping your installation current.
Liked this article? Share it