Urgent BIND Update: 14 Vulnerabilities Found, Remote Exploits Could Trigger Denial-of-Service
September 17, 2026
Several remotely exploitable CVEs have been identified in BIND, including CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736.
The ISC notes that none of these bugs are known to be exploited in the wild, but urges administrators to update BIND deployments promptly.
Affected software versions are BIND 9.21.26 and 9.20.29, with patches and guidance provided in ISC advisories and release notes.
Attack vectors include mismatched NOQNAME proofs, QTYPE TKEY queries, malformed authoritative answers, SVCB/HTTPS AliasMode records, crafted DoH requests, and 65,536-byte negative answers.
Seven additional medium-severity vulnerabilities could lead to cache poisoning, increased negative cache memory usage, CPU exhaustion, packet loss, and insertion of attacker-supplied data into a zone, enabling denial-of-service scenarios.
ISC released security updates for BIND 9 addressing 14 vulnerabilities to prevent denial-of-service conditions and related issues.
CVE-2026-77692 is notable for allowing remote, unauthenticated crashes of named via a single DoH SIG(0) request followed by connection closure.
Seven of the flaws are high-severity, potentially causing unexpected program exits, memory exhaustion, named termination, and resource exhaustion when exploited.
Additional details are available on ISC’s BIND security advisories page and BIND 9 release notes.
Summary based on 1 source
Get a daily email with more Tech stories
Source

SecurityWeek • Sep 17, 2026
ISC Patches 14 Vulnerabilities in BIND 9 Security Update