All CVEs
Vulnerability intelligence

CVE-2026-13321

ISC BIND 9 CWE-346

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS Score
8.6
High
EPSS — Exploit Probability
0.2%
Riskier than 12% of all CVEs
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

1 article across 1 outlet · first covered Jul 23, 2026 · latest Jul 23, 2026

Coverage timeline

Related CVEs — ISC