Back Feeds.Feedburner ISC Patches 14 Vulnerabilities in BIND 9 Security Update
Internet Systems Consortium (ISC) has released fresh security updates for BIND, the widely used open source DNS server software, resolving 14 vulnerabilities that could lead to denial-of-service (DoS) attacks.
Seven are high-severity flaws that could be exploited to cause an unexpected program exit, memory exhaustion, named termination, and resource exhaustion, causing DoS conditions.
The remotely exploitable bugs are tracked as CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736.
They can be triggered using mismatched NOQNAME proof, QTYPE TKEY queries, malformed answers from the authoritative server, SVCB/HTTPS AliasMode records, crafted DNS-over-HTTPS (DoH) requests, and negative answers of 65,536 bytes.
CVE-2026-77692 stands out because it can be exploited remotely without authentication to crash named with a single DoH SIG(0) request.
“An attacker can cause named to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely,” ISC explains.
The BIND updates also resolve seven medium-severity vulnerabilities that could lead to cache poisoning, increased memory usage of the negative cache, CPU exhaustion and packet loss, arbitrary attacker-supplied data being added to a zone, and DoS attacks.
All security defects were addressed with the release of BIND versions 9.21.26 and 9.20.29.
ISC says it is not aware of any of the resolved bugs being exploited in the wild, but recommends updating BIND deployments as soon as possible.
Additional information is available on the BIND security advisories page and on BIND 9’s release notes page.
Related: Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
Related: Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
Related: Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Related: Pixel Modem Zero-Day Exploited in Targeted Attacks
Ionut Arghire is an international correspondent for SecurityWeek.
More from Ionut Arghire
Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
AIUC Raises $40 Million to Certify Enterprise AI Agents
Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
280,000 Impacted by Premier Medical Group Data Breach
Chrome, Firefox Updates Patch 115 Vulnerabilities
Acronis Patches Exploited Vulnerability in cPanel Backup Plugin
Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
Exein Secures $270M at $1.7B Valuation for Physical AI Security
OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training
CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Comp AI Raises $34 Million for AI-Native Compliance and Security
Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows
Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses
AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
