Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Security Vulnerabilities

Cisco Unified CM SSRF flaw exploited in wild attacks

Attackers are actively targeting a high-severity vulnerability in Cisco Unified Communications Manager to gain root access.

Cisco Unified CM SSRF flaw exploited in wild attacks
panumas nikhomkhai · Pexels

Cisco has confirmed that a critical security flaw in its Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) is being exploited in the wild. The vulnerability, tracked as CVE-2026-20230, enables unauthenticated attackers to conduct server-side request forgery (SSRF) attacks, potentially leading to root-level access on affected devices. Cisco issued patches for the flaw on June 3, but recent reports indicate that exploitation attempts have already begun, primarily for reconnaissance purposes.

The vulnerability stems from improper input validation in the WebDialer component, which processes user-supplied URLs. Attackers can exploit this flaw by sending crafted HTTP requests containing file:// URIs, forcing the system to write arbitrary files to the underlying operating system. Successful exploitation could allow attackers to escalate privileges to root, though current activity appears focused on identifying vulnerable systems rather than deploying malicious payloads.

How the exploit works

Researchers at SSD Secure, who initially disclosed the vulnerability to Cisco, published a technical analysis detailing the attack chain. The flaw requires attackers to first obtain the target system’s hostname, which can be retrieved through reconnaissance. Once obtained, attackers can craft requests to write files to specific paths, such as /tmp/cve-2026-20230-test.txt, as observed in recent attacks. While the current exploitation appears limited to testing for vulnerable devices, the disclosure of technical details increases the risk of broader attacks.

Threat intelligence firm Defused reported observing exploitation over the weekend, originating from a single IP address. The firm noted that the flaw had not been previously recorded in exploitation databases, such as CISA’s Known Exploited Vulnerabilities (KEV) catalog, at the time of detection. Cisco has not yet responded to requests for comment on the scope of the attacks or indicators of compromise (IOCs) for defenders.

Key facts
  • CVE ID: CVE-2026-20230
  • CVSS score: 8.6 (High)
  • Affected products: Cisco Unified CM and Unified CM SME
  • Patch release date: June 3, 2026
  • Exploitation observed: June 21-22, 2026

Impact and mitigation

The vulnerability poses a significant risk to organizations using Cisco Unified CM or Unified CM SME, particularly those with internet-exposed instances. While current attacks appear to be limited to reconnaissance, the potential for root-level access makes this a critical issue for security teams. Cisco has urged customers to apply the available patches immediately, as there are no workarounds for the flaw.

For professionals

For professionals: Security teams should prioritize patching affected Cisco Unified CM and Unified CM SME deployments, particularly those accessible from the internet. Monitoring for unusual file writes, such as those in /tmp/, can help detect exploitation attempts. Given the disclosure of technical details, expect increased attacker interest in the coming weeks.

What to watch

The disclosure of the proof-of-concept exploit and the observed reconnaissance activity suggest that broader exploitation is likely. Organizations should monitor for updates from Cisco regarding IOCs or additional mitigation guidance. Security researchers may also release detection rules for SIEM and EDR platforms to help defenders identify exploitation attempts.

Discussion · coming soon

Be the first to join the thread when community discussion launches.