CISA added CVE-2015-5477 to its Known Exploited Vulnerabilities (KEV) catalogue on 8 October 2026. The vulnerability affects ISC BIND and is a data processing error that could let remote attackers cause a denial of service by sending TKEY queries.
The flaw is classified as a denial-of-service vulnerability. Its attack vector is remote: an attacker can trigger the impact with TKEY queries, according to the available description. The CVSS score is 7.5, rated HIGH. Patch status is listed as unknown, and no patch or advisory URL was provided. The issue may also affect products that use the relevant open-source component, third-party library, protocol or implementation; organisations should consult vendor guidance to establish their exposure.
KEV inclusion indicates that active exploitation has been confirmed. The supplied data does not confirm use in ransomware campaigns; ransomware use is unknown. CISA set 11 October 2026 as the remediation deadline for affected federal agencies.
CISA requires organisations to apply mitigations in accordance with vendor instructions, following applicable BOD 26-04 guidance and CISA’s Forensics Triage Requirements. Where mitigations are unavailable, agencies should discontinue use of the product. Stakeholders must assess each asset’s internet exposure and comply with applicable BOD 26-04 patching guidance, including guidance for cloud services.
The requirement directly applies to Federal Civilian Executive Branch (FCEB) agencies; all organisations should review their exposure and available vendor instructions.
See the [NVD entry](https://nvd.nist.gov/vuln/detail/CVE-2015-5477) and [CISA KEV catalogue](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) for full details.