Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities MariaDB

MariaDB Patches CVSS 10.0 RCE Flaw in Galera Cluster Replication Component

A maximum-severity OS command injection bug in MariaDB's Galera Cluster notification feature allows unauthenticated remote attackers to run arbitrary code — but only on deployments where a specific configuration option is active.

MariaDB Patches CVSS 10.0 RCE Flaw in Galera Cluster Replication Component
Sergei Starostin · Pexels

MariaDB has addressed a critical remote code execution vulnerability — CVE-2026-49261, rated CVSS 10.0 — that exists within the Galera Cluster replication subsystem. Patches shipped on May 27, 2026, roughly two weeks before public disclosure on June 11, following standard coordinated disclosure practice. The flaw carries the maximum possible CVSS score and requires no authentication, no user interaction, and no elevated privileges to exploit.

What happened

The vulnerability lives in wsrep_notify_cmd, a MariaDB configuration directive that names a shell script to execute whenever cluster membership shifts — for example, when a node joins or departs. When a new node connects, MariaDB passes that node's reported name to the script as a command-line argument. The root cause (classified as CWE-78, OS command injection) is that MariaDB failed to sanitize this name before constructing the shell invocation. An attacker who can reach the Galera replication port and present a node name containing embedded shell metacharacters can cause those commands to execute under the privileges of the MariaDB process itself.

The CVSS 3.1 vector reflects the worst-case scenario: network-reachable, low attack complexity, no credentials required, no user interaction, and high impact across confidentiality, integrity, and availability with a changed scope. The Galera replication port (TCP 4567) is typically restricted to cluster peers at the firewall level, but misconfigured environments or threats originating inside the network perimeter face no authentication barrier.

CVE-2026-49261 was not patched in isolation. The May 27 update also resolves CVE-2026-48165 and CVE-2026-48163 — both rated CVSS 8.0 and both involving parameter injection within the same wsrep notification surface. The Galera library itself was bumped to version 26.4.27 in the same release cycle. Teams should treat this as a comprehensive remediation of the wsrep notification attack surface rather than a single-issue fix.

Who is at risk

The exposure is narrowly scoped but serious within that scope. Three conditions must all be present for a system to be vulnerable: the MariaDB instance must be part of a Galera Cluster deployment; the wsrep_notify_cmd option must be explicitly set in the server configuration (it has no default value); and the server must be running an affected version. Standard single-node MariaDB installations — including the vast majority of shared hosting stacks running WordPress or similar PHP applications — are not affected by this vulnerability.

The affected release lines and their corresponding safe targets are: 10.6.x up to 10.6.26 (fix in 10.6.27), 10.11.x up to 10.11.17 (fix in 10.11.18), 11.4.x up to 11.4.11 (fix in 11.4.12), 11.8.x up to 11.8.7 (fix in 11.8.8), and 12.3.1 (fix in 12.3.2). The practical exposure sits with managed database providers, cloud database services, and infrastructure teams running clustered configurations for high availability or redundancy.

For professionals

For professionals: If upgrading immediately is not feasible, removing or commenting out the wsrep_notify_cmd directive and restarting the service eliminates the attack vector entirely. Cluster replication continues to function normally; only the membership-change notification script is disabled. Verify firewall rules restrict TCP 4567 to known cluster peers as an additional defense-in-depth measure.

What to watch

Because the public disclosure postdated the patch release by two weeks, opportunistic exploitation of unpatched systems remains plausible for any team that has not yet applied the May 27 updates. Managed database and cloud hosting providers operating Galera clusters at scale should audit configurations for active wsrep_notify_cmd directives and confirm patch status across all nodes. The breadth of affected release lines — spanning from the 10.6 long-term support branch through the 12.3 development series — suggests this component had not been subjected to rigorous input-validation review across its version history.

Companies mentioned

MariaDB

Discussion · coming soon

Be the first to join the thread when community discussion launches.