What happened cPanel declared cPanel AI generally available on September 17 in version 138, the same week the company patched CVE-2026-87899, a root escalation vulnerability reachable from an ordinary hosting account.
Why it matters to hosts If you run cPanel servers, you need to upgrade immediately to get the security patch—and you'll also inherit AI tooling that's now baked into your license, whether you've budgeted for it or not. The vulnerability lets any account holder escalate to root, which is a direct threat to your customers' isolation and your liability.
What to do Audit which of your servers are still on pre-138 builds, test the upgrade path in a staging environment, and plan your rollout this week. Document the process so your team can apply it consistently.
My view This feels like cPanel bundling AI into the license before the pricing model is even clear—Meridian is included, but Nova runs on credits 'nobody has priced' yet. The root escalation is the real story; the AI announcement is noise until the economics make sense. A hosting provider's first job is patching, not evaluating experimental AI features.
Are you planning to upgrade to cPanel 138 this week, or are you holding back until the Nova credit pricing is announced?
Launched cPanel AI generally available in version 138 (September 17), bundling Meridian AI into the license while releasing Nova on a credit-based pricing model still under development. Same week patched CVE-2026-87899, a root escalation flaw reachable from ordinary hosting accounts.
Named Sachin Puri as CEO effective October 1, 2026, succeeding the previous leadership. Puri takes the helm of the Jacksonville company behind Bluehost, HostGator, Network Solutions, and Crazy Domains.
Approached GoDaddy about a takeover on or before September 24. The announcement sent GoDaddy stock up 8.7% and Gen Digital stock down 6.1%, signaling market skepticism about the bidder's ability to fund the deal.
Released Turnstile Spin, an AI-agent feature that automatically configures Turnstile bot protection with server-side validation to prevent misconfiguration. Also reported a cross-tenant data exposure vulnerability in Cloudflare Containers, fixed in coordination with security researchers.
Launched ctrl, a new VPS control panel featuring one-click deployment for AI agents and self-hosted applications, plus integrated network firewall and modern management tools for the community hosting segment.
cPanel 138 bundles AI into your license but pricing for the Nova credit model remains undefined. This forces operators to plan for AI cost exposure without clear budget figures.
CVE-2026-87899 allows any cPanel account holder to escalate to root, putting every shared hosting server at risk. Upgrade to version 138 or later immediately to close the gap.
HostPapa rebranded its CloudBlue acquisition as Managed.com on September 17, signaling a new corporate structure for one of the hosting market's most acquisitive operators.
Gen Digital, owner of Norton and LifeLock, made a takeover approach to GoDaddy on September 24, but investor reaction suggests doubts about financing. This could reshape the domain and security software landscape if it closes.
Newfold Digital, parent of Bluehost and HostGator, named Sachin Puri as CEO effective October 1, moving leadership while maintaining executive chair oversight.
Cloudflare Containers exposed residual disk data from previous workloads across tenants; external researchers found and reported the flaw. Understanding the incident helps hosting operators evaluate multi-tenant platform safety.
Turnstile Spin uses AI agents to wire up proper server-side validation for Cloudflare's bot protection, eliminating misconfiguration that leaves sites exposed. Automated security setup is now table stakes for platform tooling.
A researcher uploaded a crafted photo through WordPress Media Library and executed arbitrary code; the libheif bug has no assigned CVE and no clear patch timeline. Shared hosting operators should monitor this closely.
WordPress 7.1.1 shipped as an unscheduled security release on September 17 to patch a comment-form XSS flaw. The payload bypassed the sanitizer, highlighting why even 'filtered' user input requires careful review.
Cloudflare reduced hash-mapping entries from 100,000 to 10,000, eliminating 100 TB of cache bloat. This demonstrates the infrastructure optimization challenges hyperscalers face as traffic scales.
Cloudflare's founders reflect on the rise of AI agents and automated traffic surpassing human activity. The letter frames shifts in internet infrastructure as foundational to hosting and edge computing strategy.
RackNerd launched ctrl, a new VPS control panel with integrated AI agent deployment, one-click app installation, and built-in firewall. This targets community providers seeking modern infrastructure without cPanel or Plesk licensing.
Canonical moved to weekly kernel releases because AI-assisted vulnerability discovery is flooding the market faster than conventional patching cadences can handle. Hosting operators need to rethink their kernel update strategy.
CloudLinux's VPS bundle applies shared hosting isolation and reliability tools to VPS environments. This addresses the growing demand for managed VPS that mimics shared hosting stability without the overhead.
nginx now supports querying which configuration file is running via signals, but not all builds expose this feature. Documentation gaps make this a silent trap for operators expecting uniform behavior across builds.
WordPress 7.1.2 is a security release closing a critical vulnerability. Immediate updates are recommended for all WordPress hosting installations.
The U.S. government allocated $1.9 billion for grid upgrades expected to unlock at least 23 gigawatts of additional capacity. This addresses the power bottleneck strangling AI data center expansion and signals sustained federal commitment to infrastructure.
Google revealed how full-stack design, low-voltage DC power, battery energy storage, and liquid cooling enable AI data centers to act as grid partners rather than consumers. This shift reduces strain on local utilities and improves sustainability metrics.
Multiple U.S. states are adopting large-load tariffs and other measures to block speculative data center projects amid public backlash. Operators planning new facilities should expect stronger regulatory scrutiny and higher permitting costs.
The DataOne data center in New Jersey faced a record $1.07 million fine for operating 62 unpermitted portable turbine generators. The penalty underscores the legal and community risk of skirting environmental permitting in dense urban areas.
The European Commission adopted a delegated regulation on September 21 creating a public environmental grading system (A–G) for all EU data centers, with labels launching August 15, 2027. Operators in Europe should begin tracking power and water metrics now.
Water consumption is shifting from a background efficiency concern to a core resilience constraint. Operators must model site-specific hydrology, local demand, and community impact rather than relying on industry-standard metrics alone.
The UK government is funding waste-heat recovery networks to feed data center exhaust into residential heating systems, including a project under the Thames. This positions data center heat as municipal infrastructure.
Alibaba Cloud announced a six-year plan to expand to 20 gigawatts of data center capacity and revealed a custom chip for AI workloads. The company is betting the AI boom will not exhaust demand despite 37 GW already under construction in the USA alone.
OpenAI and Anthropic are securing 20–30 MW colocation deals instead of waiting for megawatt-scale facilities to complete. The shift reveals a supply-demand gap and reduces risk for data center operators willing to serve quick-turn AI workloads.
Colocation is becoming the default model for enterprise AI and hybrid cloud deployments. Operators offering hybrid or multi-tenant AI hosting should expect sustained demand from enterprises avoiding hyperscaler lock-in.
Schneider Electric's modeling suggests liquid-cooled designs using higher coolant temperatures can halve water consumption in AI data centers. The optimization is technically sound but operators should verify claims independently.
Russian military attacks on Ukrainian data centers have knocked 100,000 households offline and forced local firms to migrate infrastructure abroad. The escalation illustrates physical infrastructure risk in conflict zones and its impact on connectivity. --- #HostSecure