Updated daily

HOSTING NEWS

Industry news sourced where it breaks: provider newsrooms, trade press, community boards, status pages and CVE feeds, pulled nightly and reviewed by a human editor before anything is published. Briefs link straight to the original article; we summarise, we do not republish. Analysis pieces add what only a directory of 28,000+ hosts can: reliability scores, segment and country context.

Topic
AllData CenterDomainsGeneralSecurity
Source
20iCloudflare BlogCloudflare StatusData Center DynamicsData Center KnowledgeDigitalOcean StatusDomain Name WireeUKhostHosting JournalistHostingAdviceHostingerHostList AnalysisITProLowEndTalkNVDr/webhostingSearch Engine JournalTechCrunchThe RegisterTheDomainsWeb Hosting Today
NVDSecurityAug 27, 2026
CVE-2026-19092: WordPress vulnerability, CVSS 9.8

A vulnerability tracked as CVE-2026-19092 has been disclosed in the Tutor LMS WordPress plugin, carrying a CVSS score of 9.8. Versions before 4.0.6 fail to stop request data overwriting internal variables during template rendering, letting unauthenticated users invoke arbitrary zero-argument PHP functions and view their output. Site owners should update promptly.

↗
NVDSecurityAug 19, 2026
CVE-2026-18051: WordPress vulnerability, CVSS 10

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occu

↗
NVDSecurityAug 6, 2026
CVE-2026-14812: WordPress vulnerability, CVSS 10

A vulnerability tracked as CVE-2026-14812, with a CVSS score of 10, has been disclosed for the Premium SEO WordPress plugin. According to NVD, the plugin contains a malicious, unauthenticated backdoor that creates a hidden administrator account. Some builds also allow remote code execution, server-side request forgery and arbitrary content injection.

↗
NVDSecurityAug 3, 2026
CVE-2026-15930: WordPress vulnerability, CVSS 9.4

A vulnerability tracked as CVE-2026-15930 has been identified in the Simple Membership WordPress plugin, versions before 4.7.8. According to NVD, the flaw fails to check whether user creation succeeded during registration, letting unauthenticated attackers overwrite the primary administrator's account data. The issue carries a CVSS score of 9.4. Site owners should update the plugin.

↗
NVDSecurityAug 3, 2026
CVE-2026-12965: WordPress vulnerability, CVSS 9.1

A vulnerability tracked as CVE-2026-12965 has been disclosed in the Super Store Finder WordPress plugin, affecting versions through 7.8. The flaw stems from an unsanitised parameter in an unauthenticated AJAX action, allowing attackers to perform SQL injection and extract database data without needing to log in. The issue carries a CVSS score of 9.1.

↗
HostList AnalysisSecurityJul 29, 2026Analysis
Four critical WordPress plugin takeover flaws landed in 48 hours. Here is the pattern.

Four unauthenticated takeover flaws in WordPress plugins landed in 48 hours, all CVSS 9.8. What the pattern means for hosts and site owners.

→
ITProSecurityJul 29, 2026
Orange plans €3 billion joint sovereign data center venture

Orange has outlined plans for a joint venture aimed at building a sovereign data centre platform, backed by a €3 billion investment. The venture will fold in Orange's existing data centre portfolio and target a planned capacity of 400 MW, reinforcing the company's position in European sovereign cloud infrastructure.

↗
NVDSecurityJul 28, 2026
CVE-2026-15014: WordPress vulnerability, CVSS 9.8

A vulnerability tracked as CVE-2026-15014, with a CVSS score of 9.8, has been identified in the SMS Alert plugin for WooCommerce, covering order notifications and abandoned cart recovery for WordPress. All versions up to and including 3.9.7 are affected, allowing authentication bypass and account takeover via the billing_phone parameter, according to NVD.

↗
NVDSecurityJul 28, 2026
CVE-2026-14545: WordPress vulnerability, CVSS 9.8

A vulnerability in the TrueBooker WordPress plugin, tracked as CVE-2026-14545 with a CVSS score of 9.8, has been disclosed via NVD. Versions before 1.2.4 fail to validate account ownership during password resets, letting unauthenticated attackers set arbitrary passwords, including for administrator accounts, potentially leading to full site takeover.

↗
NVDSecurityJul 27, 2026
CVE-2026-13714: WordPress vulnerability, CVSS 9.8

A critical vulnerability, CVE-2026-13714, has been identified in the Realtyna Organic IDX plugin and WPL Real Estate WordPress plugin, versions before 5.3.0. The flaw stems from unvalidated file uploads and an API secured with hardcoded credentials shared across installations. NVD rates it CVSS 9.8. Site owners should update affected plugins promptly.

↗
NVDSecurityJul 27, 2026
CVE-2026-12394: WordPress vulnerability, CVSS 9.8

A critical vulnerability, CVE-2026-12394, has been identified in the MemberGlut WordPress plugin. Versions before 1.1.5 fail to validate the role selected during front-end registration, letting unauthenticated users register accounts with any role, including administrator. This can result in full site compromise. The flaw carries a CVSS score of 9.8. Users should update the plugin promptly.

↗
ITProSecurityJul 17, 2026
Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe

UAT-11795 is weaponizing legitimate software such as WebEx and Zoom to dupe victims

↗
ITProSecurityJul 17, 2026
Airbus announces cloud deal with Scaleway in digital sovereignty push

The move by Airbus comes amidst growing concerns about digital sovereignty and the influence of US-based hyperscalers

↗
ITProSecurityJul 16, 2026
Passkeys will soon be the default authentication method in Microsoft Entra ID – here's what it means for users and when the changes come into effect

The shift to passkeys for Microsoft Entra ID comes amidst growing concerns over AI-powered phishing and identity theft

↗
ITProSecurityJul 16, 2026
CISPE vs Broadcom continues, but this time it’s bringing friends to the party in fight over VMware changes

Battle over acquisition and subsequent partnership and licensing changes continues

↗
ITProSecurityJul 9, 2026
Barracuda strengthens identity security capabilities with Evo Security acquisition

The deal expands BarracudaONE with new identity and access management capabilities tailored to the needs of MSPs

↗
ITProSecurityJul 9, 2026
Cyber researchers sound alarm over a 15-year-old Linux kernel flaw – 'GhostLock' could let hackers seize unpatched machines in just five seconds

Researchers at Nebula said the GhostLock exploit is 97% reliable and can escape containers

↗
ITProSecurityJul 9, 2026
Flaws in some of the most popular AI coding tools left developers wide open to attack

Malicious repositories can trick advanced AI agents into silently breaking out of their workspace sandboxes

↗
ITProSecurityJul 3, 2026
Cyber experts issue alert after two ransomware groups team up on ‘unprecedented’ threat campaign

The tie-up includes a new model of industrialized ransomware deployment that significantly lowers the barrier to entry for cyber crime

↗
The RegisterSecurity
Critical cPanel exploited: 'Millions' of sites could be hit

CISA has added a critical cPanel bug to its known-exploited list, confirming that attackers are already poking holes in one of the internet's most widely used hosting stacks. The vulnerability, tracked as CVE-2026-41940, carries a near-worst-case CVSS score of 9.8 and affects all supported versions ...

↗
Hosting JournalistSecurity
InMotion Hosting Says It Contained Major cPanel Flaw

cPanel released another security update on May 13, 2026, addressing five additional vulnerabilities: CVE-2026-29205, CVE-2026-29206, CVE-2026-

↗
The RegisterSecurity
CISA says n8n critical bug exploited in real-world attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that hackers are exploiting a max-severity remote code execution (RCE) vulnerability in workflow automation platform n8n. The bug was first disclosed in December, and vendors such as Resecurity said that of n8n's roughly 23...

↗
The RegisterSecurity
Critical cPanel, WHM flaw probs exploited as 0-day, pros say

Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day. Emergency patches out now for those managing the millions of

↗
HostingAdviceSecurity
27 Global Website Security Breach Statistics (2026 Data)

GoDaddy's analysis of 1.1 million infected websites revealed that malware and malicious redirects dominated the threat landscape, accounting for

↗
How this list is built

The news index is populated nightly from primary sources: provider newsrooms and blogs, independent trade press, community boards, provider status pages and vulnerability feeds. Briefs are drafted with AI assistance and every item is reviewed, edited and approved by a human editor before publication; nothing is published automatically. Briefs link out, so the original publisher gets the click and the credit, and no affiliate revenue is attached to news links. Syndication and partner sources receive no ranking consideration: the news layer and the HostList Reliability Index never touch. See About HostList for the editorial independence statement, or subscribe to the RSS feed.

RELATED

HostList Blog →WP Legends Podcast →Security Solutions →Host Rankings →Hosting M&A Desk →Ownership Groups →Full Directory →