What happened WHMCS published two security advisories on September 3, including CVE-2026-67399, an unauthenticated remote code execution vulnerability that the vendor has only patched in versions 9.0.8 and 8.13.7.
Why it matters to hosts If you run WHMCS on any version between those patches, an attacker can execute arbitrary code on your server without authentication—which means your billing system, customer data, and hosting infrastructure are all at immediate risk. Older installs and skipped updates compound the exposure.
What to do Pull your WHMCS release notes right now and confirm whether you are running 9.0.8, 8.13.7, or an older version; if you're on anything else, plan an urgent upgrade this week and test it in staging first.
My view This is a patch-management discipline problem, not a WHMCS problem—but the fact that a fix exists only for two specific versions means you cannot defer. The unauthenticated angle is what makes it bite: there is no firewall rule or authentication gateway that stops this attack. I'd also note that WordPress plugins (All-in-One WP Migration at 66% unpatched two weeks post-release) show the same pattern: hosting operators and their customers both drag on security updates, and that lag compounds the risk window.
When you push a security update to production, how do you handle customers running older versions of WHMCS or control-panel software—do you set a deadline, force the upgrade, or leave it optional?
Published CVE-2026-67399, an unauthenticated RCE; patches available only in versions 9.0.8 and 8.13.7.
Acquired Hugging Face for $12.9B; also invested $3.5B in MediaTek for NVLink Fusion and custom AI accelerators.
Suffered 33-hour BGP hijack of update infrastructure; attackers poisoned Virtualizor package distributions.
Paid $4.4B for EPC Power to add 800V DC and grid-forming technology for AI data center power delivery.
Acquired Kelvion for $4.1B to expand data center thermal management capabilities for high-density AI racks.
CVE-2026-67399 allows unauthenticated attackers to execute arbitrary code on WHMCS servers; patches are available only in 9.0.8 and 8.13.7. Any hosting operator running an older or intermediate version must upgrade immediately.
CVE-2026-19949, an unauthenticated SQL injection, was patched in version 7.110 two weeks ago; 66% of installs remain unpatched. This five-million-site plugin illustrates why patch adoption lag puts WordPress hosts at risk.
A 33-hour BGP hijack of Softaculous and Virtualizor infrastructure allowed attackers to redirect traffic and poison package updates. Hosting providers using Virtualizor for automated deployment are urged to reset credentials and audit for malicious packages.
Two unauthenticated WordPress plugin vulnerabilities—SQL injection in All-in-One WP Migration and a related flaw—went public with misleading release notes, slowing operator response to critical issues affecting millions of sites.
Wordfence documented exploitation of a critical Elementor Pro file upload vulnerability (disclosed August 19) beginning the day of disclosure on September 2. Hosting operators must assume active scanning for unpatched Elementor installs is underway now.
Softaculous and Virtualizor traffic was hijacked via BGP for 22 hours across two late-August nights, allowing attackers to poison package distributions. Customers are instructed to reset credentials and hunt for malicious packages.
WordPress announced a proactive security initiative aimed at scaling defenses as AI makes it easier for attackers to discover and exploit vulnerabilities. The program seeks to harden the ecosystem before threats outpace patches.
Cloudflare and OpenAI are combining WAF signals with Daybreak models to prioritize vulnerabilities and suggest code patches. This AI-driven remediation approach aims to reduce the noise in vulnerability discovery.
Post-quantum cryptography (PQC) certificates represent the future of SSL/TLS security as quantum computing advances. Website owners and hosting providers should begin planning migration strategies now.
Flex acquired EPC Power for $4.4B to add 800V DC and grid-forming technology for AI data center power delivery. This $4B+ bet signals that power architecture—not just capacity—is now a competitive differentiator.
A Google engineer accidentally disabled fiber connectivity at hyperscale, resulting in a partial cloud outage. The incident underscores how physical infrastructure vulnerabilities persist even at the largest operators.
Fiber access and diversity, not just power and water, now determine where data center facilities can be located and how quickly they scale. Many markets lack the redundant fiber routes required for AI infrastructure builds.
AWS is building a 420 Tbps subsea cable between Japan and Washington State, entering service in 2029 to support AI workloads. This transpacific route expansion reflects AI's demand for intercontinental network capacity.
AI data centers require fire protection strategies tailored to higher power densities and equipment value. Early design integration and holistic operational planning are essential, not just code compliance.
Corrosion risk in AI data centers begins during construction, not operations, yet preservation is rarely included in project governance. Massive capital investments are at risk from this overlooked infrastructure threat.
AI's explosive growth is forcing a fundamental reimagining of data center infrastructure, from power delivery to cooling and site strategy. Operators must rethink fundamental design assumptions.
Proton's Frankfurt data center cooling failure forced engineers to prioritize hardware preservation over service restoration. The outage highlights how scarce AI-era infrastructure makes traditional incident response trade-offs impossible.
SLB acquired Kelvion for $4.1B to add thermal management expertise for high-density AI racks. Cooling—not just compute—is now a strategic acquisition target for data center operators.
Nvidia acquired Hugging Face for $12.9B and committed to keeping the model hub open to the broader AI ecosystem. This acquisition consolidates Nvidia's control over AI infrastructure from chips to model distribution.
Nvidia's $3.5B investment in MediaTek extends NVLink Fusion and custom AI acceleration to MediaTek's platforms. This partnership signals Nvidia's strategy to embed its interconnect and software stack into partners' silicon.
DigitalOcean's market cap has surpassed GoDaddy's, reflecting investor preference for cloud infrastructure over domain and traditional hosting. Hosting company valuations now turn on developer-first positioning and SaaS-like metrics.
PostgreSQL 19 adds native SQL syntax for graph queries through multi-vendor standardization. Hosting providers serving database-heavy workloads should monitor indexing performance, as optimization still lags behind syntax support.
CERN's migration of thousands of CentOS systems to Debian underscores the long-term fallout from Red Hat's CentOS 8 end-of-life decision. Hosting operators supporting scientific and research workloads should prepare for similar shifts.
AI-assisted bug hunting is driving Linux kernel CVE counts toward 2,000 per release, overwhelming maintainers with both real flaws and low-priority noise. Hosting operators must develop smarter triage strategies rather than attempting to patch every CVE.
Verisign is raising the .net registry-level wholesale price by $1.09 to $12.00 per domain, effective March 1, 2027. Hosting providers and resellers offering .net domains should model the impact on renewal pricing and margin.
NameHero launched HeroicGuard, an email security service that filters mail before it reaches mailboxes. Hosting providers can integrate upstream email filtering to reduce spam support load and improve customer retention.
CloudLinux shared operational strategies for improving VPS profitability by automating support tasks and reducing infrastructure overhead. Hosting operators should evaluate containerization and automation tools to trim support costs.
WordPress powers 40%+ of websites; managed hosting strategies can reduce performance bottlenecks and customer support load. Operators offering WordPress-specific optimization can differentiate on performance metrics.
TSMC's equipment orders have nearly doubled in eight months as AI demand accelerates, yet CapEx is rising only ~15%, creating tool shortages that will constrain AI chip supply. Hosting operators should expect continued GPU and accelerator scarcity.
Nvidia is opening its rack-scale AI systems to custom chips, giving hyperscalers flexibility to integrate alternatives to off-the-shelf GPUs. This modularity may eventually fragment the GPU monoculture. --- #HostSecure