www.securityweek.com 17 Sept 2026, 12:39 UTC

ISC Fixes 14 BIND Flaws Allowing Remote DNS Server Crashes

ISC Fixes 14 BIND Flaws Allowing Remote DNS Server Crashes
CyberSIXT Evidence Panel

INTERNET Systems Consortium (ISC) has released security updates for BIND, the widely used open-source DNS server, addressing 14 vulnerabilities that could result in denial-of-service (DoS) attacks. Seven are rated high severity and could cause unexpected program exits, memory or other resource exhaustion, or termination of the `named` process. The remotely exploitable flaws are tracked as CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667 and CVE-2026-81736.

The issues can be triggered through several conditions, including mismatched NOQNAME proof, QTYPE TKEY queries, malformed authoritative-server answers, SVCB/HTTPS AliasMode records, crafted DNS-over-HTTPS (DoH) requests and negative answers measuring 65,536 bytes. ISC highlighted CVE-2026-77692, which can allow an unauthenticated remote attacker to crash `named` with a single DoH SIG(0) request. The attack involves sending a cryptographically invalid SIG(0) record and prematurely closing the transport connection.

The remaining seven vulnerabilities are medium severity and include potential cache poisoning, increased negative-cache memory use, CPU exhaustion, packet loss, unauthorised data added to a zone and further DoS conditions.

The defects have been fixed in BIND versions 9.21.26 and 9.20.29. ISC said it is not aware of any of the vulnerabilities being exploited in the wild, but recommends that organisations update BIND deployments as soon as possible.

View full article

Article by CyberSIXT