Written by Magento engineers

    Magento Hosting Insights

    Plain-English guides on Magento server requirements, performance and upgrades, written by the engineers who build and maintain the infrastructure.

    Latest

    Security8 September 2026 · 7 min read

    CVE-2026-67401: the cPanel bug that turns a mail user into root

    A SQL injection flaw in cPanel's EmailTrack lets an authenticated mail account write arbitrary files and finish as root. All supported versions affected. Our 11 cPanel servers were patched within hours, with timestamps.

    Read the guide →
    Checklist8 September 2026 · 10 min read

    Magento Black Friday Readiness Checklist

    Black Friday 2026 is 27 November, but if you want to change anything structural the deadline that binds is 2 October. The full four-part checklist: secure, fast, built to last, and sell more.

    Read the guide →
    Security8 September 2026 · 7 min read

    Magento Peak Season Security

    Everything you have not patched by 30 October is what you trade Black Friday on. Patch order, the files that are almost always exposed, and what 6,000 daily attack events actually look like.

    Read the guide →
    Performance8 September 2026 · 7 min read

    Magento Checkout Speed at Peak

    Homepage speed is the metric everyone reports and the page least likely to fail you. Peak breaks in the logged-in journey, where full page cache does not apply and every request hits PHP.

    Read the guide →
    Reliability8 September 2026 · 6 min read

    Magento Backup and Restore at Peak

    Ask your host to restore your store to staging and time it. In November the question is not whether a backup exists, it is whether you are down for twenty minutes or six hours.

    Read the guide →
    Merchandising8 September 2026 · 6 min read

    What Your Magento Customers Search For

    Somebody searched your store for waterproof jacket and got nothing. You stock it, you just called it something else. Magento has recorded this free since Magento 1 and almost nobody opens it.

    Read the guide →
    Active threat7 September 2026 · 8 min read

    StyleSmuggler: the Magento zero-day Adobe has not patched

    Disclosed by Sansec on 5 September, exploited since 4 September, and every version is affected including 2.4.9. Being fully patched does not help. Indicators of compromise, a read-only check script you can run on your own store, and the mitigations to apply before Adobe ships a fix.

    Read the advisory →
    Security Advisory11 August 2026 · 9 min read

    APSB26-92: Critical Adobe Commerce Account Takeover (CVE-2026-71362)

    Adobe's 11 August bulletin fixes a CVSS 9.1 incorrect authorization flaw that lets an attacker switch a customer session into someone else's account, with no login, no admin rights and no user interaction. Attack attempts started within days and are being blocked, with no confirmed compromises. Affected versions, the July-then-August patch order, and the PHP BCMath fix inside.

    Read the advisory →
    GuideAugust 2026 · 11 min read

    See What Your Magento Store Ranks For, in Plain English

    Free no-account checks for your rankings, the canonical, robots and redirect faults Magento is prone to, and whether ChatGPT and Perplexity name your store.

    Read the guide →
    Guide23 August 2026 · 9 min read

    Magento 2 Maintenance Mode Done Properly

    One command closes the store, one flag file explains every "stuck in maintenance" panic. How to enable it, keep your own access with allowed IPs, customise the 503 page and exit cleanly.

    Read the guide →
    Guide23 August 2026 · 9 min read

    Multiple Magento Stores, One Server, One Admin

    Websites vs store views, nginx routing with MAGE_RUN_CODE, per-domain SSL via SNI (no, you don't need a dedicated IP per store), and how to size a server for the combined load.

    Read the guide →
    Security23 July 2026 · 9 min read

    RefluXFS (CVE-2026-64600): The XFS Root Flaw That Turns a Shared-Hosting Neighbour Into Root

    Qualys disclosed a nine-year-old Linux XFS race condition that lets any local user become root, and it bypasses SELinux, leaves no kernel logs, and survives reboots. It hits the RHEL-family XFS default that cPanel shared Magento hosting runs on.

    Read the advisory →
    Product News15 July 2026 · 7 min read

    Your Store's Security Is Now On Screen: The Sentinel Dashboard

    Attacks neutralised in real time, an AI security analyst's report, Google health and Magento checks: live now in your client area, free for every EveryHost customer.

    Take the tour →
    Security Alert15 July 2026 · 9 min read

    APSB26-73: Adobe Ships a CVSS 10 Fix for Magento. Patch Now

    Adobe's July bulletin fixes an unauthenticated remote code execution flaw in webhooks (CVE-2026-48358, 10.0) plus four more. No exploits in the wild yet. Patch inside the window. Affected versions and isolated-patch steps inside.

    Read the alert →
    Security11 July 2026 · 9 min read

    GhostLock (CVE-2026-43499): The 15-Year-Old Linux Root Bug With a 97%-Reliable Public Exploit

    A use-after-free that sat in the Linux kernel since 2011 now has a public exploit that yields root in about five seconds, and escapes containers. If your Magento store shares a server with strangers, this is the one to check today.

    Read the advisory →
    UnsupportedUpdated 8 September 2026 · 10 min read

    Magento 2.4.6 End of Life: No Patches Since 11 August

    That deadline passed four weeks ago. Magento Open Source 2.4.6 now gets no security patches, ever, and extended support is for licensed Adobe Commerce only. What is exposed, and how to get supported again before the peak freeze.

    Read the guide →
    Security11 July 2026 · 8 min read

    Bad Epoll (CVE-2026-46242): Root via the Machinery Under Every Web Server

    A race condition in the Linux epoll subsystem, the code nginx and PHP-FPM stand on, lets an unprivileged user become root. Kernels 5.10–6.11 affected. Here's what to check.

    Read the advisory →
    Security11 July 2026 · 8 min read

    Januscape (CVE-2026-53359): The KVM Escape That Threatens VPS-Hosted Stores

    A 16-year-old KVM flaw lets a virtual machine escape to its host: root over every VPS on the box, including yours. Patching inside your VPS isn't enough; here's what to ask your host.

    Read the advisory →
    Security11 July 2026 · 7 min read

    PHP DoS Flaws (CVE-2026-12184 & CVE-2026-14355): Update Your Magento PHP

    A failed TLS handshake can now crash the PHP running your store, and take the whole PHP-FPM pool with it. Fixed in PHP 8.2.32 / 8.3.32 / 8.4.23 / 8.5.8. Here's how to check yours.

    Read the advisory →
    Security10 June 2026 · 7 min read

    The Linux Kernel Exploit That Puts Shared Magento Hosting at Risk

    A working exploit for CVE-2026-23111 is now public: local root plus container escape on multi-tenant hosts. Here's who's exposed and what to do.

    Read the analysis →
    Security10 June 2026 · 5 min read

    Critical Mirasvit Cache Warmer RCE: Patch Now

    CVE-2026-45247 is a CVSS 9.8 unauthenticated RCE on CISA's actively-exploited list. If you run Mirasvit Full Page Cache Warmer below 1.11.12, here's what to do.

    Read more →
    Security Alert17 May 2026 · 6 min read

    Adobe Commerce Security Patches May 2026 (APSB26-49)

    Adobe patched critical vulnerabilities in Magento Open Source and Adobe Commerce on 15 May. Arbitrary code execution is on the list. No exploits in the wild yet, but that window closes fast.

    Read the alert →
    Upgrade GuideUpdated 17 July 2026 · 8 min read

    Magento 2.4.9 System Requirements (Full 2026 List)

    PHP 8.4/8.5, MySQL 8.4, OpenSearch 3, Valkey 9, Varnish 8: the complete spec, what changed from 2.4.8, and how to check your host is ready.

    Read the guide →
    Release14 May 2026 · 10 min read

    Magento 2.4.9 GA: Redis to Valkey, OpenSearch 3, UK Upgrade Guide

    Magento 2.4.9 reached GA on 12 May 2026. The headline change: Valkey replaces Redis as the official cache. Plus OpenSearch 3, PHP 8.4, MySQL 8.4. UK store owner's upgrade checklist.

    Read the guide →
    Security Advisory14 May 2026 · 8 min read

    Fragnesia (CVE-2026-46300): What UK Magento Store Owners Need to Know

    A new Linux kernel privilege-escalation bug lets attackers chain a Magento webshell into full root access. Patches are rolling out now. Here's how to check if you're covered.

    Read the advisory →
    Security Update8 May 2026 · 5 min read

    EveryHost Ready to Apply Latest cPanel & WHM Security Updates

    EveryHost is preparing to apply patches for CVE-2026-29201, CVE-2026-29202 and CVE-2026-29203. Here's what managed customers need to know.

    Read the update →
    Security AlertMay 2026 · 8 min read

    CVE-2026-31431 “Copy Fail”: What Magento Store Owners Need to Know

    A new Linux kernel vulnerability gives attackers root access in 732 bytes. On shared hosting, one compromised account means every tenant is exposed. Here's what to do.

    Read the alert →
    Security AlertApril 2026 · 7 min read

    CVE-2026-41940: The cPanel Exploit That Could Delete Your Backups

    A critical authentication bypass in cPanel gave attackers root access to millions of servers, and the backups stored on them. Here's what Magento merchants need to know.

    Read the alert →
    PerformanceMay 2026 · 7 min read

    Magento Hyva Theme Hosting: What You Actually Need

    Hyva eliminates the browser bottleneck, so your server stack becomes the performance ceiling. Here's what changes when you migrate from Luma.

    Read the guide →
    UrgentApril 2026 · 5 min read

    KubeServers Is Closing: What Magento Merchants Need to Do

    KubeServers has confirmed it is shutting down. If you're a Magento merchant hosted with them, here's what happens next and how to migrate safely.

    Read the guide →
    GuideFeb 2026 · 6 min read

    Magento Dedicated Hosting UK (2026 Guide)

    A practical guide to Magento dedicated hosting in the UK: performance stack, prerequisites, and how to choose the right server.

    Read the guide →
    ChecklistFeb 2026 · 8 min read

    Magento Dedicated Hosting Buyer's Checklist (UK)

    A practical checklist to compare dedicated Magento hosting providers on hardware, stack, operations and security.

    Read the guide →
    OperationsFeb 2026 · 5 min read

    Adobe Commerce Patch Cadence: Planning Maintenance Windows Without Downtime Surprises

    Plan Magento patching around Adobe's schedule with a repeatable checklist for staging and production.

    Read the guide →
    SecurityFeb 2026 · 4 min read

    Magento Security Patch Releases Explained: What "-pN" Means and How to Apply Safely

    What security patch lines are, what to test, and the operational steps that reduce risk on live stores.

    Read the guide →
    Upgrade GuideFeb 2026 · 4 min read

    Adobe Commerce Versioning Policy: Major vs Minor vs Patch and How to Upgrade With Minimal Risk

    A clear guide to release types and a low-drama upgrade strategy that respects dependencies and extensions.

    Read the guide →

    Need a server that matches your Magento stack?

    Our engineers spec and manage dedicated Magento servers: NGINX, Varnish, OpenSearch, Valkey. No shared hosting. No tickets to level one support.