Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities Fortinet

Fortinet sandbox flaws under active attack after patches

Unidentified threat actors are exploiting three critical Fortinet sandbox vulnerabilities days after the vendor released fixes.

Fortinet sandbox flaws under active attack after patches
Brett Sayles · Pexels

Fortinet’s security sandbox appliances are facing active exploitation of three critical vulnerabilities, just days after the vendor issued patches. The flaws, all rated 9.1 on the CVSS scale, allow unauthenticated attackers to bypass authentication, escalate privileges, and execute arbitrary code remotely. While Fortinet released fixes for two of the vulnerabilities in April and the third last week, threat intelligence firm Defused confirmed exploitation began over the weekend, raising concerns about the speed of attacker adoption.

What was patched

The three vulnerabilities affect different components of Fortinet’s sandboxing solutions. CVE-2026-39813, a path traversal bug in the FortiSandbox JRPC API, enables authentication bypass via crafted HTTP requests. It impacts FortiSandbox versions 4.4.0 through 4.4.8 and 5.0.0 through 5.0.5, with fixes available in versions 4.4.9 and 5.0.6. Fortinet credited security analyst Loic Pantano for discovering this flaw.

CVE-2026-39808 and CVE-2026-25089 are both OS command injection vulnerabilities. The former affects FortiSandbox versions 4.4.0 through 4.4.8 and was patched in version 4.4.9. KPMG Spain researcher Samuel de Lucas Maroto reported this bug. The latter, CVE-2026-25089, extends to FortiSandbox Cloud and FortiSandbox PaaS WEB UI, affecting versions 4.4.0 through 4.4.8, 5.0.0 through 5.0.5, and cloud variants 5.0.4 through 5.0.5. Defused noted that no public exploit exists for this flaw, suggesting attackers may be using an unrefined or privately developed exploit.

Key facts
  • Three critical Fortinet sandbox vulnerabilities (CVSS 9.1) under active exploitation
  • CVE-2026-39813: Authentication bypass via path traversal in JRPC API
  • CVE-2026-39808: OS command injection in FortiSandbox
  • CVE-2026-25089: OS command injection in FortiSandbox, Cloud, and PaaS WEB UI
  • Exploitation detected within days of patches for CVE-2026-25089

Why exploitation is accelerating

The rapid exploitation of these vulnerabilities aligns with a broader trend of attackers targeting Fortinet products. Earlier this month, Check Point Research warned that ransomware groups had exploited a critical authentication bypass in Fortinet’s Remote Access VPN and Mobile Access deployments. The same groups were suspected of leveraging other VPN-related vulnerabilities in Fortinet’s portfolio. The pattern suggests that threat actors are prioritizing Fortinet appliances due to their widespread use in enterprise and cloud environments, where they often serve as gatekeepers for network security.

Defused’s observation that the exploit for CVE-2026-25089 appears to be "vibe coded"—potentially unstable or hastily developed—indicates that attackers are moving quickly to capitalize on the window between patch release and widespread adoption. This urgency underscores the importance of timely updates, particularly for security appliances that are directly exposed to the internet.

What administrators should do

Fortinet has not responded to inquiries about whether it has observed attacks targeting these vulnerabilities. However, the active exploitation reported by Defused leaves little room for delay. Administrators should prioritize upgrading affected FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS deployments to the patched versions immediately. For environments where immediate patching is not feasible, temporary mitigations—such as restricting access to the sandbox interfaces or implementing additional network-level controls—should be considered.

For professionals
  • Verify all FortiSandbox deployments are running patched versions (4.4.9+, 5.0.6+, or cloud equivalents)
  • Isolate sandbox interfaces from public internet access where possible
  • Monitor for unusual HTTP request patterns targeting the JRPC API or WEB UI

The speed of exploitation highlights the need for proactive vulnerability management, particularly for security appliances that are frequent targets of opportunistic attacks. Organizations relying on Fortinet’s sandboxing solutions should treat these vulnerabilities as a critical priority to prevent potential breaches or lateral movement within their networks.

Companies mentioned

Fortinet Check Point Software Defused KPMG

Discussion · coming soon

Be the first to join the thread when community discussion launches.