Internet Systems Consortium: ISC Patches 14 Vulnerabilities in BIND 9 Security Update

Internet Systems Consortium: ISC Patches 14 Vulnerabilities in BIND 9 Security Update

ISC Patches 14 Vulnerabilities in BIND DNS Software, Including High-Severity DoS Flaws

The Internet Systems Consortium (ISC) has released critical security updates for BIND, the widely deployed open-source DNS server software, addressing 14 vulnerabilities that could enable denial-of-service (DoS) attacks and other disruptive exploits.

Among the fixes, seven high-severity flaws (tracked as CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736) could be exploited remotely to trigger program crashes, memory exhaustion, or resource depletion, leading to service disruptions. Notably, CVE-2026-77692 allows unauthenticated attackers to crash the named process with a single malformed DNS-over-HTTPS (DoH) request containing an invalid SIG(0) record, followed by premature connection termination.

The remaining seven medium-severity vulnerabilities could result in cache poisoning, excessive memory usage, CPU exhaustion, or arbitrary data injection into DNS zones. Exploits include crafted QTYPE TKEY queries, oversized negative responses, and SVCB/HTTPS AliasMode records.

ISC has patched the flaws in BIND versions 9.21.26 and 9.20.29, with no evidence of active exploitation in the wild. Organizations are advised to update their deployments promptly. Full details are available in the BIND security advisories and release notes.

Source: https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/

Internet Systems Consortium TPRM report: https://www.rankiteo.com/company/internet-systems-consortium

"id": "int1789669809",
"linkid": "internet-systems-consortium",
"type": "Vulnerability",
"date": "9/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': 'Users of BIND DNS software',
                        'industry': 'Technology/Software',
                        'name': 'Internet Systems Consortium (ISC)',
                        'type': 'Organization'}],
 'attack_vector': 'Remote Exploitation',
 'description': 'The Internet Systems Consortium (ISC) has released critical '
                'security updates for BIND, the widely deployed open-source '
                'DNS server software, addressing 14 vulnerabilities that could '
                'enable denial-of-service (DoS) attacks and other disruptive '
                'exploits. Among the fixes, seven high-severity flaws could be '
                'exploited remotely to trigger program crashes, memory '
                'exhaustion, or resource depletion, leading to service '
                'disruptions. The remaining seven medium-severity '
                'vulnerabilities could result in cache poisoning, excessive '
                'memory usage, CPU exhaustion, or arbitrary data injection '
                'into DNS zones.',
 'impact': {'downtime': 'Service disruptions (DoS)',
            'operational_impact': 'Program crashes, memory exhaustion, '
                                  'resource depletion, cache poisoning, CPU '
                                  'exhaustion',
            'systems_affected': 'BIND DNS Server Software'},
 'investigation_status': 'Vulnerabilities patched; no evidence of active '
                         'exploitation',
 'post_incident_analysis': {'corrective_actions': 'Patching and security '
                                                  'updates',
                            'root_causes': 'Software vulnerabilities in BIND '
                                           'DNS software'},
 'recommendations': 'Organizations are advised to update their BIND '
                    'deployments to versions 9.21.26 or 9.20.29 promptly.',
 'references': [{'source': 'BIND Security Advisories'}],
 'response': {'communication_strategy': 'Security advisories and release notes '
                                        'published',
              'containment_measures': 'Security updates released (BIND '
                                      'versions 9.21.26 and 9.20.29)',
              'remediation_measures': 'Patch deployment advised'},
 'title': 'ISC Patches 14 Vulnerabilities in BIND DNS Software, Including '
          'High-Severity DoS Flaws',
 'type': 'Vulnerability Disclosure',
 'vulnerability_exploited': ['CVE-2026-80274',
                             'CVE-2026-76163',
                             'CVE-2026-19666',
                             'CVE-2026-81563',
                             'CVE-2026-77692',
                             'CVE-2026-19667',
                             'CVE-2026-81736']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.