Join our Beta Program today

HostSecure.org - Industry News

HSC Industry Digest Weekly Recap - September 07, 2026
Weekly Recap · for the week of Sep 1 to Sep 7, 2026

WHMCS Unauthenticated RCE Requires Immediate Upgrade; Two-Thirds of WordPress Migration Installs Still Unpatched

Industry News - September 7, 2026

My Take

What happened WHMCS published two security advisories on September 3, including CVE-2026-67399, an unauthenticated remote code execution vulnerability that the vendor has only patched in versions 9.0.8 and 8.13.7.

Why it matters to hosts If you run WHMCS on any version between those patches, an attacker can execute arbitrary code on your server without authentication—which means your billing system, customer data, and hosting infrastructure are all at immediate risk. Older installs and skipped updates compound the exposure.

What to do Pull your WHMCS release notes right now and confirm whether you are running 9.0.8, 8.13.7, or an older version; if you're on anything else, plan an urgent upgrade this week and test it in staging first.

My view This is a patch-management discipline problem, not a WHMCS problem—but the fact that a fix exists only for two specific versions means you cannot defer. The unauthenticated angle is what makes it bite: there is no firewall rule or authentication gateway that stops this attack. I'd also note that WordPress plugins (All-in-One WP Migration at 66% unpatched two weeks post-release) show the same pattern: hosting operators and their customers both drag on security updates, and that lag compounds the risk window.

When you push a security update to production, how do you handle customers running older versions of WHMCS or control-panel software—do you set a deadline, force the upgrade, or leave it optional?

Executive Summary
This week's hosting landscape is dominated by two urgent security stories: an unauthenticated remote code execution in WHMCS that requires immediate patching to 9.0.8 or 8.13.7, and a broader WordPress ecosystem where critical SQL injection patches remain undeployed on two-thirds of affected sites two weeks after release. In parallel, a 33-hour BGP hijack of Softaculous and Virtualizor infrastructure exposed supply-chain risks in hosting automation tooling. Outside security, major AI-driven infrastructure reshuffles continue: Nvidia's $12.9B acquisition of Hugging Face signals consolidation in model ecosystems, while Flex's $4.4B EPC Power deal and SLB's $4.1B Kelvion acquisition underpin the 800V and thermal-management overhaul demanded by AI data center densities.
Key Themes
Patch adoption lag persists despite high severity:: two-thirds of All-in-One WP Migration installs unpatched after 14 days, and Elementor attacks began the same day the flaw was disclosed, indicating attackers move faster than many operators deploy fixes.
Supply-chain attacks on hosting tools are evolving:: the Softaculous BGP hijack poisoned Virtualizor updates for 22 hours, a direct threat to hosting providers who depend on third-party automation and distribution.
Notable Players
WHMCS:

Published CVE-2026-67399, an unauthenticated RCE; patches available only in versions 9.0.8 and 8.13.7.

Nvidia:

Acquired Hugging Face for $12.9B; also invested $3.5B in MediaTek for NVLink Fusion and custom AI accelerators.

Softaculous / Virtualizor:

Suffered 33-hour BGP hijack of update infrastructure; attackers poisoned Virtualizor package distributions.

Flex:

Paid $4.4B for EPC Power to add 800V DC and grid-forming technology for AI data center power delivery.

SLB:

Acquired Kelvion for $4.1B to expand data center thermal management capabilities for high-density AI racks.

Top Stories

WHMCS Has an Unauthenticated RCE. The Fix Exists Only for 9.0.8 and 8.13.7.

CVE-2026-67399 allows unauthenticated attackers to execute arbitrary code on WHMCS servers; patches are available only in 9.0.8 and 8.13.7. Any hosting operator running an older or intermediate version must upgrade immediately.

Nearly Two-Thirds of All-in-One WP Migration Installs Remain Unpatched Two Weeks Later

CVE-2026-19949, an unauthenticated SQL injection, was patched in version 7.110 two weeks ago; 66% of installs remain unpatched. This five-million-site plugin illustrates why patch adoption lag puts WordPress hosts at risk.

An Attacker Hijacked Hetzner IP Space and Poisoned a Virtualizor Update

A 33-hour BGP hijack of Softaculous and Virtualizor infrastructure allowed attackers to redirect traffic and poison package updates. Hosting providers using Virtualizor for automated deployment are urged to reset credentials and audit for malicious packages.

A High-Severity Patch for Five Million WordPress Sites Was Labeled as a Text Fix

Two unauthenticated WordPress plugin vulnerabilities—SQL injection in All-in-One WP Migration and a related flaw—went public with misleading release notes, slowing operator response to critical issues affecting millions of sites.

Attacks on the Elementor Pro Flaw Began the Day It Was Disclosed

Wordfence documented exploitation of a critical Elementor Pro file upload vulnerability (disclosed August 19) beginning the day of disclosure on September 2. Hosting operators must assume active scanning for unpatched Elementor installs is underway now.

Security & Compliance

33-hour BGP hijack of Softaculous traffic prompts security scramble

Softaculous and Virtualizor traffic was hijacked via BGP for 22 hours across two late-August nights, allowing attackers to poison package distributions. Customers are instructed to reset credentials and hunt for malicious packages.

WordPress Announces A Proactive Security Initiative via @sejournal, @martinibuster

WordPress announced a proactive security initiative aimed at scaling defenses as AI makes it easier for attackers to discover and exploit vulnerabilities. The program seeks to harden the ecosystem before threats outpace patches.

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models

Cloudflare and OpenAI are combining WAF signals with Daybreak models to prioritize vulnerabilities and suggest code patches. This AI-driven remediation approach aims to reduce the noise in vulnerability discovery.

PQC certificates: What website owners should know about the future of SSL/TLS security

Post-quantum cryptography (PQC) certificates represent the future of SSL/TLS security as quantum computing advances. Website owners and hosting providers should begin planning migration strategies now.

Cloud & Infrastructure

Flex Pays $4.4B for EPC Power as AI Data Centers Push 800V Architecture

Flex acquired EPC Power for $4.4B to add 800V DC and grid-forming technology for AI data center power delivery. This $4B+ bet signals that power architecture—not just capacity—is now a competitive differentiator.

Google engineer unplugged every fiber they could see and

A Google engineer accidentally disabled fiber connectivity at hyperscale, resulting in a partial cloud outage. The incident underscores how physical infrastructure vulnerabilities persist even at the largest operators.

Could Fiber Be the Next Big Bottleneck in Data Center Growth?

Fiber access and diversity, not just power and water, now determine where data center facilities can be located and how quickly they scale. Many markets lack the redundant fiber routes required for AI infrastructure builds.

AWS Wires a New US AI Route Across the Pacific

AWS is building a 420 Tbps subsea cable between Japan and Washington State, entering service in 2029 to support AI workloads. This transpacific route expansion reflects AI's demand for intercontinental network capacity.

How AI Is Changing Fire Protection in Modern Data Centers

AI data centers require fire protection strategies tailored to higher power densities and equipment value. Early design integration and holistic operational planning are essential, not just code compliance.

The Corrosion Blind Spot in the AI Buildout

Corrosion risk in AI data centers begins during construction, not operations, yet preservation is rarely included in project governance. Massive capital investments are at risk from this overlooked infrastructure threat.

Meeting AI Demand: Alternate Power, Design, and Site Strategy

AI's explosive growth is forcing a fundamental reimagining of data center infrastructure, from power delivery to cooling and site strategy. Operators must rethink fundamental design assumptions.

Proton's Frankfurt Outage Report: 20 Minutes to Critical, and Hardware Too Scarce to Sacrifice

Proton's Frankfurt data center cooling failure forced engineers to prioritize hardware preservation over service restoration. The outage highlights how scarce AI-era infrastructure makes traditional incident response trade-offs impossible.

SLB's $4.1B Kelvion Deal Expands AI Data Center Push

SLB acquired Kelvion for $4.1B to add thermal management expertise for high-density AI racks. Cooling—not just compute—is now a strategic acquisition target for data center operators.

Acquisitions & Market

Nvidia buys Hugging Face for $12.9B, promises not to squeeze too hard

Nvidia acquired Hugging Face for $12.9B and committed to keeping the model hub open to the broader AI ecosystem. This acquisition consolidates Nvidia's control over AI infrastructure from chips to model distribution.

Nvidia pours $3.5 billion into MediaTek

Nvidia's $3.5B investment in MediaTek extends NVLink Fusion and custom AI acceleration to MediaTek's platforms. This partnership signals Nvidia's strategy to embed its interconnect and software stack into partners' silicon.

DigitalOcean's Market Cap Is Now Higher Than GoDaddy's. What Five Public Multiples Say About Hosting Valuations.

DigitalOcean's market cap has surpassed GoDaddy's, reflecting investor preference for cloud infrastructure over domain and traditional hosting. Hosting company valuations now turn on developer-first positioning and SaaS-like metrics.

Technology & Tools

PostgreSQL 19 connects the dots with standardized graph queries

PostgreSQL 19 adds native SQL syntax for graph queries through multi-vendor standardization. Hosting providers serving database-heavy workloads should monitor indexing performance, as optimization still lags behind syntax support.

CERN moves thousands of accelerator control computers to Debian

CERN's migration of thousands of CentOS systems to Debian underscores the long-term fallout from Red Hat's CentOS 8 end-of-life decision. Hosting operators supporting scientific and research workloads should prepare for similar shifts.

Linux kernel nears record 2,000 vulnerabilities per release as AI bug hunters scour 40 million lines of code

AI-assisted bug hunting is driving Linux kernel CVE counts toward 2,000 per release, overwhelming maintainers with both real flaws and low-priority noise. Hosting operators must develop smarter triage strategies rather than attempting to patch every CVE.

Domains & DNS

Verisign Lifts .net Wholesale From $10.91 to $12.00, Effective March 1, 2027

Verisign is raising the .net registry-level wholesale price by $1.09 to $12.00 per domain, effective March 1, 2027. Hosting providers and resellers offering .net domains should model the impact on renewal pricing and margin.

Web Hosting & Performance

1,000+ Junk Emails a Day, Brought Under Control by One DNS Change

NameHero launched HeroicGuard, an email security service that filters mail before it reaches mailboxes. Hosting providers can integrate upstream email filtering to reduce spam support load and improve customer retention.

How to Improve VPS Profitability While Reducing Support Load

CloudLinux shared operational strategies for improving VPS profitability by automating support tasks and reducing infrastructure overhead. Hosting operators should evaluate containerization and automation tools to trim support costs.

How to reduce WordPress performance bottlenecks with managed hosting

WordPress powers 40%+ of websites; managed hosting strategies can reduce performance bottlenecks and customer support load. Operators offering WordPress-specific optimization can differentiate on performance metrics.

AI & Semiconductors

TSMC fab equipment demand nearly doubles in six months

TSMC's equipment orders have nearly doubled in eight months as AI demand accelerates, yet CapEx is rising only ~15%, creating tool shortages that will constrain AI chip supply. Hosting operators should expect continued GPU and accelerator scarcity.

Nvidia, MediaTek Bring Custom Chips to AI Racks

Nvidia is opening its rack-scale AI systems to custom chips, giving hyperscalers flexibility to integrate alternatives to off-the-shelf GPUs. This modularity may eventually fragment the GPU monoculture. --- #HostSecure