Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities

CISA mandates patch for exploited Joomla plugin flaw

U.S. federal agencies must secure vulnerable Joomla sites by Friday after active exploitation of a critical plugin vulnerability.

CISA mandates patch for exploited Joomla plugin flaw
Rubaitul Azad · Unsplash

A critical security flaw in a widely used Joomla plugin has prompted urgent action from U.S. cybersecurity authorities after evidence emerged of active exploitation. The vulnerability, identified as CVE-2026-48907, affects the Widget Factory Joomla Content Editor (JCE), a WYSIWYG editor plugin for the Joomla content management system. Attackers can exploit the flaw without authentication, enabling remote code execution through low-complexity attacks on unpatched installations.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog on Tuesday and issued a directive requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by Friday. The order follows Binding Operational Directive (BOD) 26-04, which mandates prioritized patching for vulnerabilities posing significant risks to federal systems. CISA emphasized that the flaw is a frequent attack vector for malicious actors and urged agencies to evaluate internet-exposed assets for compliance with the directive.

What happened

The vulnerability stems from an improper access control issue in the JCE plugin, allowing unauthenticated users to create new editor profiles and upload malicious PHP code. Widget Factory, the plugin’s developer, released a patch in early June with version 2.9.99.6 of JCE Pro, warning users of active exploitation and publicly available exploit code. The company noted that automated attacks were targeting Joomla sites regardless of whether public registration was enabled, making all installations vulnerable.

Key facts
  • Vulnerability: CVE-2026-48907 (CVSS: 10.0, maximum severity)
  • Affected software: Widget Factory Joomla Content Editor (JCE) Pro versions prior to 2.9.99.6
  • Exploitation: Remote code execution via unauthenticated attacks
  • Patch release: June 2024 (JCE Pro 2.9.99.6)
  • CISA deadline: Federal agencies must patch by August 9, 2024

CISA’s directive underscores the urgency of the situation, as the flaw meets several high-risk criteria: it is actively exploited, vulnerable assets are often exposed online, and exploitation can be automated at scale. The agency also highlighted that the vulnerability grants attackers partial or total control of targeted systems, further elevating its threat level.

Remediation and risks

Widget Factory advised users to update to JCE Pro 2.9.99.6 or later immediately but cautioned that patching alone does not clean already compromised sites. For sites that may have been breached before updating, the company recommended a multi-step remediation process:

  1. Back up rogue profiles for forensic analysis.
  2. Update the plugin to the latest version.
  3. Delete attacker-created profiles.
  4. Reset all passwords, including those for administrator accounts, databases, and hosting services.
  5. Conduct a full server-side malware scan to detect additional implants or malicious tools.
For professionals

For professionals: Joomla site operators, particularly those managing federal or enterprise environments, should prioritize patching this vulnerability due to its active exploitation. Even sites without public registration are at risk, as automated attacks do not require user interaction. Post-patch, conduct a thorough audit for signs of compromise, including unauthorized profiles or unexpected file modifications.

The incident reflects broader challenges in securing web applications, where third-party plugins often introduce vulnerabilities that can be exploited at scale. Security teams are advised to monitor for unusual activity, such as unexpected profile creations or file uploads, and to implement layered defenses to mitigate risks from unpatched software.

What to watch

While the immediate focus is on patching, the long-term implications for Joomla site security remain a concern. The JCE plugin’s widespread use means many installations may remain unpatched, prolonging the window of opportunity for attackers. Additionally, the incident highlights the need for proactive vulnerability management, particularly for plugins that extend the functionality of popular content management systems.

CISA’s directive may also prompt private-sector organizations to review their own patching practices, particularly for vulnerabilities listed in the Known Exploited Vulnerabilities Catalog. As exploitation becomes more automated, the time between vulnerability disclosure and widespread attacks continues to shrink, increasing the pressure on security teams to respond rapidly.

Companies mentioned

Widget Factory CISA

Discussion · coming soon

Be the first to join the thread when community discussion launches.