CVE Tools

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

The Hacker NewsBy The Hacker News

PatchBIND 9

Our summary

ISC has released BIND 9.20.29 and 9.21.26 to address 14 vulnerabilities: CVE-2026-77692, CVE-2026-76163, CVE-2026-19667, CVE-2026-19666, CVE-2026-80274, CVE-2026-19662, CVE-2026-81563, CVE-2026-81736, CVE-2026-19668, CVE-2026-75029, CVE-2026-19941, CVE-2026-77119, CVE-2026-19033, and CVE-2026-78301. CVE-2026-77692 allows an unauthenticated party to crash named on BIND 9 servers handling DNS-over-HTTPS with a malformed SIG(0) request, while other issues can crash resolvers, exhaust CPU or memory, or enable DNS data integrity attacks under specific conditions. ISC reports no active exploitation; administrators should update BIND 9, noting that the unsupported 9.18 branch has no fixes for 12 of these issues.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store