Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Security Vulnerabilities

MariaDB Patches CVSS 10.0 RCE Flaw in Galera Cluster Replication Component

A maximum-severity OS command injection bug in MariaDB's Galera Cluster notification feature allows unauthenticated remote attackers to run arbitrary code — but only on deployments where a specific configuration option is active.

MariaDB Patches CVSS 10.0 RCE Flaw in Galera Cluster Replication Component
Sergei Starostin · Pexels

MariaDB has addressed a critical remote code execution vulnerability — CVE-2026-49261, rated CVSS 10.0 — that exists within the Galera Cluster replication subsystem. Patches shipped on May 27, 2026, roughly two weeks before public disclosure on June 11, following standard coordinated disclosure practice. The flaw carries the maximum possible CVSS score and requires no authentication, no user interaction, and no elevated privileges to exploit.

What happened

The vulnerability lives in wsrep_notify_cmd, a MariaDB configuration directive that names a shell script to execute whenever cluster membership shifts — for example, when a node joins or departs. When a new node connects, MariaDB passes that node's reported name to the script as a command-line argument. The root cause (classified as CWE-78, OS command injection) is that MariaDB failed to sanitize this name before constructing the shell invocation. An attacker who can reach the Galera replication port and present a node name containing embedded shell metacharacters can cause those commands to execute under the privileges of the MariaDB process itself.

The CVSS 3.1 vector reflects the worst-case scenario: network-reachable, low attack complexity, no credentials required, no user interaction, and high impact across confidentiality, integrity, and availability with a changed scope. The Galera replication port (TCP 4567) is typically restricted to cluster peers at the firewall level, but misconfigured environments or threats originating inside the network perimeter face no authentication barrier.

CVE-2026-49261 was not patched in isolation. The May 27 update also resolves CVE-2026-48165 and CVE-2026-48163 — both rated CVSS 8.0 and both involving parameter injection within the same wsrep notification surface. The Galera library itself was bumped to version 26.4.27 in the same release cycle. Teams should treat this as a comprehensive remediation of the wsrep notification attack surface rather than a single-issue fix.

Who is at risk

The exposure is narrowly scoped but serious within that scope. Three conditions must all be present for a system to be vulnerable: the MariaDB instance must be part of a Galera Cluster deployment; the wsrep_notify_cmd option must be explicitly set in the server configuration (it has no default value); and the server must be running an affected version. Standard single-node MariaDB installations — including the vast majority of shared hosting stacks running WordPress or similar PHP applications — are not affected by this vulnerability.

The affected release lines and their corresponding safe targets are: 10.6.x up to 10.6.26 (fix in 10.6.27), 10.11.x up to 10.11.17 (fix in 10.11.18), 11.4.x up to 11.4.11 (fix in 11.4.12), 11.8.x up to 11.8.7 (fix in 11.8.8), and 12.3.1 (fix in 12.3.2). The practical exposure sits with managed database providers, cloud database services, and infrastructure teams running clustered configurations for high availability or redundancy.

For professionals

For professionals: If upgrading immediately is not feasible, removing or commenting out the wsrep_notify_cmd directive and restarting the service eliminates the attack vector entirely. Cluster replication continues to function normally; only the membership-change notification script is disabled. Verify firewall rules restrict TCP 4567 to known cluster peers as an additional defense-in-depth measure.

What to watch

Because the public disclosure postdated the patch release by two weeks, opportunistic exploitation of unpatched systems remains plausible for any team that has not yet applied the May 27 updates. Managed database and cloud hosting providers operating Galera clusters at scale should audit configurations for active wsrep_notify_cmd directives and confirm patch status across all nodes. The breadth of affected release lines — spanning from the 10.6 long-term support branch through the 12.3 development series — suggests this component had not been subjected to rigorous input-validation review across its version history.

Discussion · coming soon

Be the first to join the thread when community discussion launches.