Industry stats Updated Sep 2026 All domains worldwide 401.6M registered names +2.3% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 40.7% of all sites · 58.9% of CMS sites W3Techs · 1 Sep 2026 Shopify 5.3% of all sites · 7.7% of CMS sites W3Techs · 1 Sep 2026 Wix 4.2% of all sites · 6.1% of CMS sites W3Techs · 1 Sep 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Sep 2026 Joomla 1.1% of all sites · 1.7% of CMS sites W3Techs · 1 Sep 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Sep 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Sep 2026 No CMS detected 30.9% of all sites W3Techs · 1 Sep 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Deal Automattic → WebHosting.com domain · Automattic acquired the WebHosting.com domain in July 2026. No public press release or purchase price disclosed; domain now resolves to a 'coming soon' page with Automattic branding. No hosting business or customer migration was included in the deal. 2026 Industry stats Updated Sep 2026 All domains worldwide 401.6M registered names +2.3% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 40.7% of all sites · 58.9% of CMS sites W3Techs · 1 Sep 2026 Shopify 5.3% of all sites · 7.7% of CMS sites W3Techs · 1 Sep 2026 Wix 4.2% of all sites · 6.1% of CMS sites W3Techs · 1 Sep 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Sep 2026 Joomla 1.1% of all sites · 1.7% of CMS sites W3Techs · 1 Sep 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Sep 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Sep 2026 No CMS detected 30.9% of all sites W3Techs · 1 Sep 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Deal Automattic → WebHosting.com domain · Automattic acquired the WebHosting.com domain in July 2026. No public press release or purchase price disclosed; domain now resolves to a 'coming soon' page with Automattic branding. No hosting business or customer migration was included in the deal. 2026
Security Vulnerabilities WHMCS

WHMCS patches critical RCE flaw in billing platform

Unauthenticated code execution bug affects versions 8.0+; update required

WHMCS patches critical RCE flaw in billing platform
Brett Sayles · Pexels

WHMCS has addressed two significant security vulnerabilities in its widely used billing and automation software, including a critical unauthenticated remote code execution (RCE) flaw. The updates, released earlier this month, affect installations running versions 8.0 and later, with no patch available for older branches within the 8.x series outside of upgrading to a supported release.

What was fixed

The primary vulnerability, tracked as CVE-2026-67399, allows attackers to execute arbitrary code on vulnerable WHMCS servers without requiring authentication. The flaw impacts all versions from 8.0 onward, with fixes delivered in WHMCS 9.0.8 and 8.13.7. Administrators running versions 8.0 through 8.12 must upgrade to at least 8.13.7 or migrate to the 9.x branch, as no security updates will be provided for those intermediate releases.

Alongside the RCE flaw, WHMCS resolved CVE-2026-67398, a missing-authorization vulnerability in the bundled 2CheckOut payment gateway module. This issue, disclosed by a researcher identified as "boomerang," enables unauthenticated users to access customer personal data, including names, addresses, contact details, and payment information. The vulnerability affects installations running WHMCS 4.5.0 or later and carries a CVSS 4.0 score of 8.2, classified as High severity.

Key facts
  • CVE-2026-67399: Critical RCE, unauthenticated, affects WHMCS 8.0+
  • CVE-2026-67398: High-severity data exposure in 2CheckOut module, affects WHMCS 4.5.0+
  • Fixes released in WHMCS 9.0.8 and 8.13.7 on 3 September 2026
  • No in-branch fix for WHMCS 8.0–8.12; upgrade required
  • Temporary workaround for 2CheckOut flaw: deactivate module and switch gateways

Why the vulnerabilities matter

WHMCS serves as a central hub for many hosting providers, managing customer accounts, billing, and automated service provisioning. The platform integrates with control panels like cPanel, Plesk, and DirectAdmin, as well as domain registrars and payment processors. These integrations often involve storing API credentials and other sensitive configuration data, which could be exposed if an attacker successfully exploits the RCE vulnerability.

While WHMCS has not reported any confirmed exploitation of CVE-2026-67399 in the wild, the public disclosure of the flaw increases the risk of attack. Security researchers note that once a vulnerability is made public, attackers can analyze the differences between patched and unpatched versions to develop exploits. The timing of this disclosure, less than a month after a separate authentication vulnerability in cPanel (CVE-2026-41940), underscores the importance of promptly patching core hosting infrastructure.

Steps for administrators

WHMCS administrators should prioritize upgrading to a patched version. The process involves:

  1. Version check: Log into the WHMCS admin area and navigate to Utilities → Update WHMCS to confirm the installed version.
  2. Upgrade path: Install WHMCS 9.0.8 or 8.13.7. Those running versions 8.0–8.12 must upgrade to a newer release, as no security fixes will be backported to those branches.
  3. Testing: If the installation includes custom modules, hooks, or third-party integrations, test the upgrade in a staging environment first to avoid compatibility issues.
  4. Mitigation for 2CheckOut users: If immediate upgrading is not possible, deactivate the 2CheckOut module and switch to an alternative payment gateway. This step only addresses the data-exposure flaw, not the RCE vulnerability.
  5. Post-upgrade review: After applying the update, examine server and WHMCS access logs for unusual activity. Rotate API keys, passwords, and integration credentials if any indicators of compromise are detected.
For professionals

For professionals: Hosting providers relying on WHMCS for billing and automation should treat this update as urgent. The RCE flaw could allow attackers to compromise not only customer data but also credentials used to connect WHMCS to other critical systems. Delaying patching increases exposure to potential exploitation, particularly as details of the vulnerability become more widely known.

Companies mentioned

WHMCS 2CheckOut

Discussion · coming soon

Be the first to join the thread when community discussion launches.