Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Security Vulnerabilities

CISA mandates patch for exploited Joomla plugin flaw

U.S. federal agencies must secure vulnerable Joomla sites by Friday after active exploitation of a critical plugin vulnerability.

CISA mandates patch for exploited Joomla plugin flaw
Rubaitul Azad · Unsplash

A critical security flaw in a widely used Joomla plugin has prompted urgent action from U.S. cybersecurity authorities after evidence emerged of active exploitation. The vulnerability, identified as CVE-2026-48907, affects the Widget Factory Joomla Content Editor (JCE), a WYSIWYG editor plugin for the Joomla content management system. Attackers can exploit the flaw without authentication, enabling remote code execution through low-complexity attacks on unpatched installations.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog on Tuesday and issued a directive requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by Friday. The order follows Binding Operational Directive (BOD) 26-04, which mandates prioritized patching for vulnerabilities posing significant risks to federal systems. CISA emphasized that the flaw is a frequent attack vector for malicious actors and urged agencies to evaluate internet-exposed assets for compliance with the directive.

What happened

The vulnerability stems from an improper access control issue in the JCE plugin, allowing unauthenticated users to create new editor profiles and upload malicious PHP code. Widget Factory, the plugin’s developer, released a patch in early June with version 2.9.99.6 of JCE Pro, warning users of active exploitation and publicly available exploit code. The company noted that automated attacks were targeting Joomla sites regardless of whether public registration was enabled, making all installations vulnerable.

Key facts
  • Vulnerability: CVE-2026-48907 (CVSS: 10.0, maximum severity)
  • Affected software: Widget Factory Joomla Content Editor (JCE) Pro versions prior to 2.9.99.6
  • Exploitation: Remote code execution via unauthenticated attacks
  • Patch release: June 2024 (JCE Pro 2.9.99.6)
  • CISA deadline: Federal agencies must patch by August 9, 2024

CISA’s directive underscores the urgency of the situation, as the flaw meets several high-risk criteria: it is actively exploited, vulnerable assets are often exposed online, and exploitation can be automated at scale. The agency also highlighted that the vulnerability grants attackers partial or total control of targeted systems, further elevating its threat level.

Remediation and risks

Widget Factory advised users to update to JCE Pro 2.9.99.6 or later immediately but cautioned that patching alone does not clean already compromised sites. For sites that may have been breached before updating, the company recommended a multi-step remediation process:

  1. Back up rogue profiles for forensic analysis.
  2. Update the plugin to the latest version.
  3. Delete attacker-created profiles.
  4. Reset all passwords, including those for administrator accounts, databases, and hosting services.
  5. Conduct a full server-side malware scan to detect additional implants or malicious tools.
For professionals

For professionals: Joomla site operators, particularly those managing federal or enterprise environments, should prioritize patching this vulnerability due to its active exploitation. Even sites without public registration are at risk, as automated attacks do not require user interaction. Post-patch, conduct a thorough audit for signs of compromise, including unauthorized profiles or unexpected file modifications.

The incident reflects broader challenges in securing web applications, where third-party plugins often introduce vulnerabilities that can be exploited at scale. Security teams are advised to monitor for unusual activity, such as unexpected profile creations or file uploads, and to implement layered defenses to mitigate risks from unpatched software.

What to watch

While the immediate focus is on patching, the long-term implications for Joomla site security remain a concern. The JCE plugin’s widespread use means many installations may remain unpatched, prolonging the window of opportunity for attackers. Additionally, the incident highlights the need for proactive vulnerability management, particularly for plugins that extend the functionality of popular content management systems.

CISA’s directive may also prompt private-sector organizations to review their own patching practices, particularly for vulnerabilities listed in the Known Exploited Vulnerabilities Catalog. As exploitation becomes more automated, the time between vulnerability disclosure and widespread attacks continues to shrink, increasing the pressure on security teams to respond rapidly.

Discussion · coming soon

Be the first to join the thread when community discussion launches.