Internet Systems Consortium disclosed nine vulnerabilities in BIND 9 and released patched versions 9.20.26 and 9.21.24. The most severe issue, CVE-2026-13321 (CVSS 8.6), allows a remotely exploitable DNSSEC validation bypass by accepting signed NSEC records whose Next Domain Name points outside the signer’s zone, enabling cross-zone cache poisoning with authenticated denial responses. ISC also disclosed CVE-2026-11721, a high-severity cache poisoning flaw tied to label-count discrepancies in RRSIG and wildcard synthesis, and CVE-2026-10723, which can let attackers forge authenticated NXDOMAIN responses for sibling zones through incorrect acceptance of child-zone NSEC3 records. ISC said no active exploitation was known at disclosure time and reported no workaround for the affected releases.
The remaining flaws include several remotely exploitable denial-of-service and resource exhaustion bugs affecting DNSSEC-validating resolvers and other BIND components. CVE-2026-11622 can drive memory consumption far beyond configured limits during random-subdomain attacks against DNSSEC-signed zones, while CVE-2026-11605 can force excessive CPU use by making BIND validate unnecessary but valid RRSIG records. CVE-2026-13204, CVE-2026-12617, and CVE-2026-10822 can cause named to exit unexpectedly under specific malformed or specially ordered DNS responses, and CVE-2026-11331 can bypass wildcard RPZ CNAME policies and also trigger a crash with overly long query names. ISC advised users of affected 9.11, 9.18, 9.20, 9.21, and Supported Preview Edition branches to upgrade to the nearest patched supported release.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-22, ISC released updated BIND 9 versions 9.20.26 and 9.21.24 to address the disclosed vulnerabilities. The oss-sec posting said the embargo ended with the disclosure, allowing prepared packages to be released publicly.
On 2026-07-22, ISC publicly disclosed nine vulnerabilities affecting BIND 9, spanning cache poisoning, DNSSEC validation bypass, denial of service, RPZ policy bypass, and resource exhaustion issues. ISC stated no active exploitation was known at disclosure time and advised users to upgrade.
ISC said CVE-2026-10822, a malformed PRIVATEDNS KEY/DNSKEY record issue that can make BIND abort, was identified during internal testing.
ISC said CVE-2026-11622, which can drive resolver memory usage far beyond configured limits under a random subdomain attack, was discovered during internal testing.
ISC credited Laith Mash'al (0xmshal) with reporting CVE-2026-11331, a flaw that can bypass wildcard CNAME RPZ policy rules and may also cause BIND 9 to exit unexpectedly.
ISC said CVE-2026-13204, a denial-of-service flaw involving mixed NSEC and NSEC3 validation states, was reported to the company by Qifan Zhang of Palo Alto Networks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
19 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcekb.isc.org
Open sourcesecurity-tracker.debian.org
Open sourcedownloads.isc.org
Open sourcedownloads.isc.org
Open sourcekb.isc.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.