Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Security Vulnerabilities

Cisco patches exploited SD-WAN vManage zero-day flaw

The vulnerability allowed attackers to escalate privileges to root via crafted HTTP requests.

Cisco patches exploited SD-WAN vManage zero-day flaw
Egor Komarov · Pexels

Cisco has addressed a critical security flaw in its Catalyst SD-WAN Manager, previously known as SD-WAN vManage, which was exploited in attacks to escalate privileges to root. The vulnerability, identified as CVE-2026-20262, affects all deployment models of the software, including on-premises, cloud-managed, and government-specific environments.

The issue arises from inadequate validation of user-provided input during file uploads. Attackers with low-level authentication could exploit this by sending specially crafted HTTP requests to an affected API endpoint, enabling them to create or overwrite files on the underlying operating system. These files could later be leveraged to gain root privileges.

What happened

Cisco’s Product Security Incident Response Team (PSIRT) confirmed that the vulnerability was actively exploited in the wild. The company released patches for multiple software releases, including versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2. While Cisco did not disclose details about the attacks, it provided indicators of compromise (IOCs) for administrators to check their logs. Specifically, admins should inspect vmanage-server, vmanage-appserver, and serviceproxy-access logs for unauthorized uploads of index.jsp or .war files.

Key facts
  • Vulnerability: CVE-2026-20262 (privilege escalation to root)
  • Affected software: Cisco Catalyst SD-WAN Manager (all deployment types)
  • Exploitation method: Crafted HTTP requests to API endpoints
  • Fixed releases: 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2
  • IOCs: Unauthorized uploads of index.jsp or .war files in logs

Why it matters

Catalyst SD-WAN Manager is a central management platform for SD-WAN deployments, allowing administrators to oversee up to 6,000 devices from a single dashboard. A compromise of this system could grant attackers broad control over an organization’s network infrastructure, including the ability to manipulate configurations, intercept traffic, or deploy further malicious payloads. The active exploitation of this flaw underscores the urgency for organizations to apply the patches immediately.

This is not the first time Cisco’s SD-WAN software has been targeted. Earlier this year, the company patched multiple vulnerabilities in the same product line, including CVE-2026-20133 (information disclosure), CVE-2026-20128, and CVE-2026-20122 (both exploited in the wild). In May, Cisco also addressed a maximum-severity authentication bypass flaw (CVE-2026-20182) that allowed attackers to gain admin privileges on unpatched devices. Most recently, in June, another zero-day (CVE-2026-20245) was disclosed, which also enabled root-level access.

For professionals

For professionals: Administrators should prioritize patching affected systems and reviewing logs for signs of compromise. Given the history of active exploitation in this product line, assume that unpatched instances are at high risk. Consider isolating management interfaces from broader network access until updates are applied.

What to watch

Cisco’s SD-WAN portfolio has become a frequent target for attackers, likely due to its widespread adoption in enterprise and government networks. Organizations should monitor for further vulnerabilities in this software, particularly those that could lead to privilege escalation or remote code execution. Additionally, security teams should evaluate their detection capabilities, as Cisco noted that many successful attacks go undetected by existing monitoring tools. The company’s reference to a whitepaper highlighting gaps in threat detection—where only 14% of successful attacks trigger alerts—suggests that many environments may need to enhance their logging and alerting mechanisms.

Discussion · coming soon

Be the first to join the thread when community discussion launches.