Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Security Vulnerabilities

phpBB patches decade-old auth bypass that exposes all forum accounts

A critical authentication flaw introduced to phpBB roughly ten years ago lets an unauthenticated attacker log in as any registered user, including site administrators, with a single HTTP request.

phpBB patches decade-old auth bypass that exposes all forum accounts
Pixabay · Pexels

A vulnerability hiding inside the phpBB codebase for approximately a decade has been patched in the stable release branch, following a responsible disclosure that prompted a rapid four-day turnaround from the project's maintainers.

Researchers at application security firm Aikido identified the flaw on June 2 and submitted it through phpBB's HackerOne Vulnerability Disclosure Program. Maintainers responded immediately and shipped a fix on June 6 in phpBB 3.3.17. The 4.x alpha branch — currently at 4.0.0-a2 — remains unpatched; Aikido advises operators running that branch to pull directly from the project's master repository until a formal 4.x release is available.

Key facts
  • Affected versions: phpBB 3.3.16 and below, and 4.0.0-a2
  • Fixed in: phpBB 3.3.17 (released June 6)
  • 4.x branch: no stable patch yet; upgrade to current master
  • Flaw introduced: approximately 10 years ago, present across all 3.x and 4.x releases
  • CVE identifier: none assigned at time of reporting

The vulnerability requires no preconditions — it is exploitable in phpBB's default configuration and demands no prior knowledge of the target installation. Aikido confirmed that a single crafted HTTP request is sufficient to authenticate as an arbitrary account.

Successful exploitation against an administrator account would let an attacker read all private messages stored on the forum, manipulate or delete posts and user records, impersonate moderators or staff members, and alter site content. Aikido noted that remote code execution is not achievable through this vector alone, because the Admin Control Panel enforces a separate password verification step that this bypass does not circumvent.

Target selection is straightforward by default: phpBB exposes a public member list out of the box, giving attackers a ready-made directory of usernames to impersonate.

The research team withheld the full technical write-up to give forum operators adequate time to patch and reached out directly to administrators of prominent phpBB-powered communities. Aikido intends to publish a detailed disclosure at a later date but has not announced a specific timeline.

One operational caveat: applying the 3.3.17 update may disrupt forums that rely on OAuth-based sign-in. The OAuth redirect handler was relocated during the fix, which can break existing integrations. Aikido characterized this as straightforward to resolve in most deployments.

For professionals

For professionals: Hosting providers and managed-forum operators running phpBB should prioritize updating to 3.3.17 — or to master for 4.x installs — and verify that OAuth redirect URIs are updated post-upgrade. Given the absence of a CVE identifier, automated vulnerability scanners may not flag this flaw, making manual version checks and direct communication with affected tenants especially important.

phpBB is a PHP-based open-source forum platform that saw its widest adoption in the early-to-mid 2000s. Despite a shift in community platforms toward hosted SaaS alternatives, the software still underpins thousands of active forums.

The disclosure underscores a persistent risk in long-running open-source projects: a subtle logic error can persist across major version branches for years without detection, particularly in software whose security audit frequency may not match its deployment footprint. No other vendors or third-party integrations have been identified as affected by this specific flaw.

Discussion · coming soon

Be the first to join the thread when community discussion launches.