Urgent BIND Update: 14 Vulnerabilities Found, Remote Exploits Could Trigger Denial-of-Service

September 17, 2026
Urgent BIND Update: 14 Vulnerabilities Found, Remote Exploits Could Trigger Denial-of-Service
  • Several remotely exploitable CVEs have been identified in BIND, including CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736.

  • The ISC notes that none of these bugs are known to be exploited in the wild, but urges administrators to update BIND deployments promptly.

  • Affected software versions are BIND 9.21.26 and 9.20.29, with patches and guidance provided in ISC advisories and release notes.

  • Attack vectors include mismatched NOQNAME proofs, QTYPE TKEY queries, malformed authoritative answers, SVCB/HTTPS AliasMode records, crafted DoH requests, and 65,536-byte negative answers.

  • Seven additional medium-severity vulnerabilities could lead to cache poisoning, increased negative cache memory usage, CPU exhaustion, packet loss, and insertion of attacker-supplied data into a zone, enabling denial-of-service scenarios.

  • ISC released security updates for BIND 9 addressing 14 vulnerabilities to prevent denial-of-service conditions and related issues.

  • CVE-2026-77692 is notable for allowing remote, unauthenticated crashes of named via a single DoH SIG(0) request followed by connection closure.

  • Seven of the flaws are high-severity, potentially causing unexpected program exits, memory exhaustion, named termination, and resource exhaustion when exploited.

  • Additional details are available on ISC’s BIND security advisories page and BIND 9 release notes.

Summary based on 1 source


Get a daily email with more Tech stories

Source

More Stories