cPanel patched a privilege escalation running from an ordinary hosting account to root, plus a WP Toolkit flaw reaching other accounts' databases. Three builds shipped September 22, no severity score is published, and one researcher is credited on four root-level flaws across cPanel and Plesk.
nginx can now be asked which configuration it is actually running, a question that had no answer before 1.31.5, and a reload now returns an HTTP status code with the logs attached. The Control API came out of the paid NGINX Plus release, and it ships with no authentication of its own.
WordPress 7.1.1 fixes CVE-2026-93485, a stored XSS delivered through the ordinary comment form by an anonymous visitor and missed by wp_kses. Two of the other ten fixes came from Anthropic, and three in ten sites run a version 6 branch reached only by a backport.
A cPanel advisory of September 14 covers a LiteSpeed Enterprise flaw that lets a hosting account past CageFS to root. LiteSpeed has since shipped 6.3.7 three times in six days, each build with a security change, and a server patched on the day of the advisory is no longer on the latest one.
cPanel patched CVE-2026-65643: an account holder able to add parked or addon domains could create arbitrary files and reach root, taking every site on the server. All supported versions were affected. No CVE record, no CVSS and no exploitation status published so far.
Namecheap's second hosting outage in 13 days hit 78 shared servers on August 26 and was resolved after two hours and twenty minutes of status updates. Unlike the Phoenix cooling failure, this one ended with no cause given.
InMotion is switching on Monarx ThreatShield fleet-wide, blocking attacks inside the PHP runtime rather than filtering requests in front of it. Its own July incident report, with two sites taken over in under half a minute each, documents the problem this product class targets.
Plesk's August 25 advisories cover three flaws reachable from an ordinary customer account: arbitrary file reads, cross-tenant database access, and root through two extensions. The extension fixes ship separately, and administrators report the Migrator update is not arriving.
GoDaddy's Node.js Hosting runs applications as persistent processes on plans that already exist, at a flat price. Its published deploy contract sets the limits that decide fit: outbound traffic on ports 80 and 443 only, no external databases, and no outbound SMTP.
Forminator's file upload flaw scores 9.8 and needs no authentication, but it takes a form with both an upload and a select field, and the default .htaccess meant to stop execution does nothing on NGINX. The changelog records twelve security releases in nineteen days.
cPanel patched three vulnerabilities on July 29, across every supported branch. Two matter most on shared servers: an unauthenticated request-smuggling bug that can alter other users' responses, and a database flaw that lets an ordinary account reach admin rights and possibly the host itself.
First edition of our quarterly index, measured July 29: SiteGround renews at up to 5.3x, the price-lock club at 1.0x, and GoDaddy, HostGator, and Namecheap mid-band at 1.7–3.7x. At every provider with a full plan range, the entry plan renews at a higher multiple than the top plan.
AI infrastructure competes with traditional hosting for the same DRAM. VPS and dedicated servers have repriced. Shared hosting adjusts last - with 3-5 year hardware cycles, the bill arrives at renewal. Two cost vectors are already building.
by Damian Andruszkiewicz · 10 Feb 2026 · 4 min read
TL;DR - if 2024 was about post‑COVID normalization, 2025 was about pressure - on margins, positioning, and on the long‑term credibility of the traditional shared hosting model. Growth didn’t collapse, but cracks
Imagine signing up for web hosting and having someone build your website for free. No fuss, no page builders, no AI involved. You just sit down, fill out a form, and the DreamHost team takes care of the rest. From scratch. By hand. And it looks good. Sounds absurd? Yet it’s real - this is an actual offer.
Indonesia is one of the fastest-growing digital markets in the world, driven by a large population, increasing internet penetration, and a dynamic business environment. With a rapidly evolving digital landscape, businesses must navigate language preferences, diverse payment systems, customer service expectations, and regulatory changes to succeed.