Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities Cloudflare

Cloudflare WAF blocks two critical WordPress vulnerabilities

Cloudflare deploys WAF rules to mitigate unauthenticated RCE and SQLi flaws in WordPress 6.8+

Cloudflare WAF blocks two critical WordPress vulnerabilities
Tima Miroshnichenko · Pexels

Cloudflare has rolled out Web Application Firewall (WAF) protections to shield WordPress sites from two newly disclosed vulnerabilities rated as high and critical severity. The rules target an unauthenticated remote code execution (RCE) flaw and a SQL injection vulnerability, both affecting recent WordPress releases. Protections were activated at 17:03 UTC on the day of disclosure, covering all Cloudflare customers with proxied traffic, including free-tier users, though patching remains the recommended fix for site operators.

What the vulnerabilities entail

The two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, exploit distinct attack vectors within WordPress. The RCE vulnerability (CVE-2026-63030) allows unauthenticated attackers to execute arbitrary code via the REST API’s batch endpoint, provided no persistent object cache is in use. No user interaction or credentials are required for exploitation, and the flaw is present in WordPress versions 6.9 and later. The SQL injection issue (CVE-2026-60137), rated high severity, affects versions 6.8 and above, enabling crafted input to manipulate database queries.

WordPress has released patches in version 7.0.2, with backports available for 6.9.5, 6.8.6, and 7.1 Beta 2. Versions prior to 6.8 are unaffected. The WordPress security team has prioritized automatic updates for affected sites, though manual verification of patch installation is advised. Cloudflare’s WAF rules act as a temporary safeguard, blocking malicious requests at the network edge while operators apply updates.

Key facts
  • CVE-2026-63030: Unauthenticated RCE in WordPress 6.9+, critical severity
  • CVE-2026-60137: SQL injection in WordPress 6.8+, high severity
  • Patched versions: 7.0.2, 6.9.5, 6.8.6, 7.1 Beta 2
  • Cloudflare WAF rules deployed: 17:03 UTC, 17 July 2026
  • Affected sites: WordPress 6.8 and later (RCE only in 6.9+)

How Cloudflare’s protections work

Cloudflare has implemented two WAF rules to detect and block exploitation attempts. The first rule targets the SQL injection vulnerability by identifying malicious parameter values before they reach the WordPress application. The second rule focuses on the RCE flaw, intercepting requests attempting to access the vulnerable REST API endpoint. Both rules are enabled by default with a block action for all Cloudflare customers, including those on free plans, though users can override this behavior.

For customers on Pro, Business, or Enterprise plans, Cloudflare recommends verifying that the managed ruleset is active and reviewing any overrides that might change the default block action to log-only. Free-tier users are protected automatically but should still monitor security events for requests matching either rule. Cloudflare has published documentation outlining steps to confirm rule activation and adjust settings if necessary.

For professionals

For professionals: Operators should prioritize patching WordPress to the latest secure version, as WAF rules are a temporary mitigation. Verify that automatic updates have applied the fix, and check Cloudflare WAF logs for blocked requests targeting the REST API batch endpoint, which may indicate attempted exploitation.

Risks and next steps

While Cloudflare’s WAF rules reduce exposure, they do not address the underlying vulnerabilities. Site operators must update WordPress to a patched version to fully resolve the risks. Cloudflare has stated it will continue monitoring traffic for new attack variations and update the rules as needed. The company credited the WordPress security team for coordinating the disclosure, allowing infrastructure providers to prepare protections ahead of public release.

WordPress’s automatic update mechanism is expected to mitigate the issue for most sites, but manual checks are recommended for environments where auto-updates are disabled or delayed. Operators unable to patch immediately should ensure Cloudflare’s WAF rules remain active and review logs for suspicious activity targeting the affected endpoints.

Companies mentioned

Cloudflare WordPress

Discussion · coming soon

Be the first to join the thread when community discussion launches.