Skip to content
Multiple CVEs Discovered in BIND 9 Affecting DNS Resolvers

Multiple CVEs Discovered in BIND 9 Affecting DNS Resolvers

First seen 17 Sep 2026, 01:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 03:51 UTC
  • Three critical CVEs affect BIND 9, leading to potential denial-of-service.
  • Organizations with public DNS resolvers are at high risk.
  • Immediate patching is recommended, but no active exploitation is confirmed.

Three critical vulnerabilities (CVE-2026-76163, CVE-2026-80274, CVE-2026-19666) were published on September 16, 2026, affecting BIND 9 versions 9.11.0 through 9.21.25. These vulnerabilities can lead to unexpected program exits and denial-of-service conditions for DNS resolvers. CVE-2026-76163 allows attackers to exploit a TKEY query without a global options block, while CVE-2026-80274 and CVE-2026-19666 involve malformed DNS responses causing resolver crashes. Organizations operating public recursive resolvers, especially those using DNS64, are particularly at risk. Immediate remediation is advised, but no active exploitation has been confirmed. The vulnerabilities have been rated with high availability risks but lack PoC or KEV indicators. Administrators are urged to apply patches promptly and monitor resolver logs for anomalies.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
CVE-2026-76163 published
CVE-2026-76163 disclosed, affecting BIND 9 configurations without global options, leading to denial-of-service.
kb.isc.org
2026-09-16
CVE-2026-80274 published
CVE-2026-80274 disclosed, affecting BIND 9 resolvers querying DNSSEC-signed zones, causing unexpected exits.
kb.isc.org
2026-09-16
CVE-2026-19666 published
CVE-2026-19666 disclosed, affecting DNS64-enabled resolvers with malformed responses leading to crashes.
kb.isc.org
2026-09-17
Advisories published
Multiple advisories issued, urging immediate patching and monitoring for affected BIND 9 versions.
Redpacketsecurity

More articles in this cluster (6)

Following this threat?

Track CVE-2026-19666 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed