Industry stats Updated Sep 2026 All domains worldwide 401.6M registered names +2.3% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 40.7% of all sites · 58.9% of CMS sites W3Techs · 1 Sep 2026 Shopify 5.3% of all sites · 7.7% of CMS sites W3Techs · 1 Sep 2026 Wix 4.2% of all sites · 6.1% of CMS sites W3Techs · 1 Sep 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Sep 2026 Joomla 1.1% of all sites · 1.7% of CMS sites W3Techs · 1 Sep 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Sep 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Sep 2026 No CMS detected 30.9% of all sites W3Techs · 1 Sep 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Deal Automattic → WebHosting.com domain · Automattic acquired the WebHosting.com domain in July 2026. No public press release or purchase price disclosed; domain now resolves to a 'coming soon' page with Automattic branding. No hosting business or customer migration was included in the deal. 2026 Industry stats Updated Sep 2026 All domains worldwide 401.6M registered names +2.3% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 40.7% of all sites · 58.9% of CMS sites W3Techs · 1 Sep 2026 Shopify 5.3% of all sites · 7.7% of CMS sites W3Techs · 1 Sep 2026 Wix 4.2% of all sites · 6.1% of CMS sites W3Techs · 1 Sep 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Sep 2026 Joomla 1.1% of all sites · 1.7% of CMS sites W3Techs · 1 Sep 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Sep 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Sep 2026 No CMS detected 30.9% of all sites W3Techs · 1 Sep 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Deal Automattic → WebHosting.com domain · Automattic acquired the WebHosting.com domain in July 2026. No public press release or purchase price disclosed; domain now resolves to a 'coming soon' page with Automattic branding. No hosting business or customer migration was included in the deal. 2026
Security Vulnerabilities Sansec

Magento zero-day exploited despite full patching

A critical unpatched flaw in Magento and Adobe Commerce allows RCE without authentication.

Magento zero-day exploited despite full patching
X · Unsplash

A critical security vulnerability in Magento and Adobe Commerce is under active exploitation, allowing unauthenticated remote code execution (RCE) even on fully patched systems. The flaw, dubbed StyleSmuggler by Dutch security firm Sansec, was first observed in attacks on 4 September 2026. Adobe has acknowledged the issue but has not yet released a patch, CVE identifier, or public advisory as of 7 September 2026. The discovery underscores risks for hosting providers, as the exploit persists outside the web root and evades conventional detection methods.

How the exploit works

StyleSmuggler leverages an injection flaw in Magento’s template system, specifically targeting the "styles" properties to bypass existing safeguards. The attack unfolds in two stages: first, the attacker injects malicious PHP code, often by triggering a failure report. Magento then executes this code while rendering a failed payment email, regardless of whether the email is delivered or opened. Sansec confirmed the exploit works across all current Magento versions, including 2.4.7, 2.4.8, and 2.4.9, and does not require user interaction or session storage modifications.

Key facts
  • First confirmed exploitation: 4 September 2026 at 22:20 UTC
  • Affected versions: Magento Open Source 2.4.6-p15, 2.4.7-p2, 2.4.8, 2.4.9
  • Mitigation: Disable GraphQL or deploy third-party blocking tools (e.g., Sansec Shield)
  • Adobe’s next scheduled security release: 8 September 2026 (no confirmation if it will address this flaw)
  • Implant persistence: Cron entries, kernel thread disguises, or self-relaunching processes

The backdoor implant, written in Rust, disguises itself as legitimate system processes such as [kworker/u:8:0], fc-cache, or chronyd. It installs outside the web root—typically in the site user’s home directory or /tmp—and communicates via UDP packets masquerading as NTP traffic. Persistence mechanisms vary, including cron entries written directly to spool files to avoid detection in system logs. Sansec warns that an empty crontab does not guarantee a clean system, as some implants restore themselves within seconds of removal.

Impact on hosting providers

The first two confirmed victims were Magento Open Source stores hosted by Disrex, a provider running its own infrastructure under the RexHosting brand. One store, running Magento 2.4.8 with Sansec’s blocking product enabled, was compromised at 23:10 UTC on 4 September—hours before Sansec released its first blocking rules for the flaw. The second store, on Magento 2.4.7-p2, was breached at 00:55 UTC the following day. Both incidents occurred before mitigation measures were available, highlighting the exploit’s speed and stealth.

For professionals

For professionals: Hosting providers should audit authentication logs for repeated crontab: (www-data) AUTH (crontab command not allowed) entries, which indicate failed persistence attempts. Disabling GraphQL is the only confirmed mitigation but may break headless storefronts. Sansec’s indicators of compromise (IOCs) can be used to scan fleets independently of its commercial tools.

Sansec’s advisory notes that session hardening—such as moving sessions to Redis or databases—does not prevent the attack. Additionally, a separate threat actor has been observed dropping web shells into Magento’s product image cache (pub/media), complicating cleanup efforts. The implant’s ability to evade detection by mimicking kernel threads or time-sync processes further complicates incident response for providers managing shared or dedicated environments.

What to watch

Adobe’s next scheduled security release is 8 September 2026, but it remains unclear whether it will include a fix for StyleSmuggler. Until then, hosting providers and merchants must rely on third-party tools or temporary GraphQL disablement. Sansec continues to update its advisory as the investigation progresses, with new indicators and behaviors emerging daily. Providers should monitor for updates and prepare for potential widespread exploitation, given the flaw’s low barrier to entry and high impact.

Companies mentioned

Sansec Adobe Disrex

Discussion · coming soon

Be the first to join the thread when community discussion launches.