Industry stats Updated Sep 2026 All domains worldwide 401.6M registered names +2.3% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 40.7% of all sites · 58.9% of CMS sites W3Techs · 1 Sep 2026 Shopify 5.3% of all sites · 7.7% of CMS sites W3Techs · 1 Sep 2026 Wix 4.2% of all sites · 6.1% of CMS sites W3Techs · 1 Sep 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Sep 2026 Joomla 1.1% of all sites · 1.7% of CMS sites W3Techs · 1 Sep 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Sep 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Sep 2026 No CMS detected 30.9% of all sites W3Techs · 1 Sep 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Deal Automattic → WebHosting.com domain · Automattic acquired the WebHosting.com domain in July 2026. No public press release or purchase price disclosed; domain now resolves to a 'coming soon' page with Automattic branding. No hosting business or customer migration was included in the deal. 2026 Industry stats Updated Sep 2026 All domains worldwide 401.6M registered names +2.3% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 40.7% of all sites · 58.9% of CMS sites W3Techs · 1 Sep 2026 Shopify 5.3% of all sites · 7.7% of CMS sites W3Techs · 1 Sep 2026 Wix 4.2% of all sites · 6.1% of CMS sites W3Techs · 1 Sep 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Sep 2026 Joomla 1.1% of all sites · 1.7% of CMS sites W3Techs · 1 Sep 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Sep 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Sep 2026 No CMS detected 30.9% of all sites W3Techs · 1 Sep 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Deal Automattic → WebHosting.com domain · Automattic acquired the WebHosting.com domain in July 2026. No public press release or purchase price disclosed; domain now resolves to a 'coming soon' page with Automattic branding. No hosting business or customer migration was included in the deal. 2026
Security Vulnerabilities cPanel

cPanel patches root escalation from hosting accounts

A flaw let any cPanel user gain root access without extra conditions.

cPanel patches root escalation from hosting accounts
panumas nikhomkhai · Pexels

Control-panel vendor cPanel has patched a security flaw that allowed any authenticated user to escalate privileges to root level on shared hosting servers. The vulnerability, tracked internally as CVE-2026-87899, was disclosed alongside two other issues in advisories published on September 22, 2026.

What was fixed

The most severe flaw resided in cPanel’s CalDAV and CardDAV functionality, which has been handled by the cpdavd service since version 120. An attacker with a valid cPanel account could exploit the flaw to execute arbitrary code as the root user, gaining full control over the server. No additional conditions or permissions were required beyond holding an account, meaning any customer on a shared server could potentially compromise the entire machine.

The fix was delivered in builds 11.134.0.57, 11.136.0.41, and 11.138.0.8 for standard cPanel and WHM deployments, and 11.138.1.11 for WP Squared. These updates also addressed a separate issue in the same service that allowed users to read calendars and contacts belonging to other accounts, though not modify them or escalate privileges further.

A third vulnerability, unrelated to cpdavd, affected WP Toolkit, a separate package that ships with cPanel. The flaw allowed authenticated users to modify databases owned by other accounts. The advisory did not specify whether data could also be read or if access to WP Toolkit itself was required. The fix for this issue was delivered in WP Toolkit version 6.11.3, which must be applied separately from the cPanel updates.

Key facts
  • Flaw CVE-2026-87899 allowed root access from any cPanel account
  • Patched builds: 11.134.0.57, 11.136.0.41, 11.138.0.8, and 11.138.1.11 (WP Squared)
  • WP Toolkit fix (6.11.3) requires separate installation
  • No CVSS score or CVE record published as of September 24, 2026
  • No temporary mitigation provided

Broader context

The September 22 advisories mark the second targeted security release for cPanel’s 134 and 136 update lines in a two-week span. The first, issued on September 8, addressed a flaw in the EmailTrack feature. A third build, released on September 10, was also labeled as security-related but included routine fixes alongside hardening measures.

During the same period, Plesk, another control-panel product under the WebPros umbrella, patched two critical vulnerabilities in its Backup Manager. Both flaws, reported by the same researcher, allowed authenticated users to gain root access. One involved a symlink race during restores, while the other permitted arbitrary file writes as root. These were fixed in Plesk for Linux versions 18.0.80.7 and 18.0.79.11. Plesk for Windows was unaffected.

All four vulnerabilities—two in cPanel and two in Plesk—were reported by security researcher Ali Mustafa, working alone or with a collaborator known as abed1526. None of the advisories mentioned evidence of active exploitation, and no severity scores or CVE records were available as of September 24.

What operators should do

Shared-hosting providers and administrators running cPanel or Plesk should apply the updates immediately. For cPanel, this means upgrading to one of the patched builds for the 134, 136, or 138 lines, depending on the deployment. WP Toolkit users must also run the separate installer for version 6.11.3, as the cPanel update does not cover it. Plesk users should upgrade to 18.0.80.7 or 18.0.79.11 for Linux.

For professionals
  • Servers running cPanel 120 or later are affected; earlier versions are not
  • WP Toolkit updates are not automatic—manual installation is required
  • No workaround exists; patching is the only remediation

The lack of CVSS scores or published CVE records leaves administrators with little guidance on prioritization. However, the potential for full server compromise from a low-privilege account makes these updates critical for any environment where untrusted users have cPanel or Plesk access.

Companies mentioned

cPanel Plesk WebPros

Discussion · coming soon

Be the first to join the thread when community discussion launches.