Skip to content
ISC Patches 14 Vulnerabilities in BIND 9 Security Update

ISC Patches 14 Vulnerabilities in BIND 9 Security Update

Feeds.Feedburner Ionut Arghire September 17, 2026

Internet Systems Consortium (ISC) has released fresh security updates for BIND, the widely used open source DNS server software, resolving 14 vulnerabilities that could lead to denial-of-service (DoS) attacks.

Seven are high-severity flaws that could be exploited to cause an unexpected program exit, memory exhaustion, named termination, and resource exhaustion, causing DoS conditions.

The remotely exploitable bugs are tracked as CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736.

They can be triggered using mismatched NOQNAME proof, QTYPE TKEY queries, malformed answers from the authoritative server, SVCB/HTTPS AliasMode records, crafted DNS-over-HTTPS (DoH) requests, and negative answers of 65,536 bytes.

CVE-2026-77692 stands out because it can be exploited remotely without authentication to crash named with a single DoH SIG(0) request.

“An attacker can cause named to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely,” ISC explains.

The BIND updates also resolve seven medium-severity vulnerabilities that could lead to cache poisoning, increased memory usage of the negative cache, CPU exhaustion and packet loss, arbitrary attacker-supplied data being added to a zone, and DoS attacks.

All security defects were addressed with the release of BIND versions 9.21.26 and 9.20.29.

ISC says it is not aware of any of the resolved bugs being exploited in the wild, but recommends updating BIND deployments as soon as possible.

Additional information is available on the BIND security advisories page and on BIND 9’s release notes page.

Related: Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

Related: Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases

Related: Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Related: Pixel Modem Zero-Day Exploited in Targeted Attacks

Ionut Arghire is an international correspondent for SecurityWeek.

More from Ionut Arghire

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

AIUC Raises $40 Million to Certify Enterprise AI Agents

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

280,000 Impacted by Premier Medical Group Data Breach

Chrome, Firefox Updates Patch 115 Vulnerabilities

Acronis Patches Exploited Vulnerability in cPanel Backup Plugin

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

Exein Secures $270M at $1.7B Valuation for Physical AI Security

OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

Comp AI Raises $34 Million for AI-Native Compliance and Security

Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses

AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

Flipboard Whatsapp Whatsapp Email