Internet Systems Consortium (ISC) released security updates for 14 vulnerabilities in BIND 9 and its Supported Preview Edition. Seven high-severity flaws can remotely crash named or exhaust resolver resources. Most notably, CVE-2026-77692 (CVSS 7.5) lets an unauthenticated attacker terminate named with a crafted DNS-over-HTTPS request carrying an invalid SIG(0) record and an early connection close. Other high-severity issues include assertion failures, use-after-free conditions, and memory exhaustion involving TKEY, DNS64, DNSSEC validation, negative caching, and SVCB/HTTPS processing.
Seven medium-severity vulnerabilities add risks of CPU and memory exhaustion, packet loss, and DNS integrity compromise. CVE-2026-19033 can apply unauthenticated IXFR data to a secondary zone before TSIG validation, while CVE-2026-78301, CVE-2026-77119, and CVE-2026-19941 can enable attacker-controlled referrals or cache poisoning under applicable conditions. Affected releases include BIND 9 lines through 9.18.50, 9.20.27, and 9.21.25; ISC fixed the issues in BIND 9.20.29 and 9.21.26 and advises administrators to deploy the applicable patched release promptly. ISC reported no known active exploitation or workarounds; organizations should prioritize internet-facing authoritative servers, recursive resolvers, and DoH-enabled deployments, including BIND packages on Debian systems identified by current Nessus checks.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-931 warning that multiple BIND 9 release lines were affected and advising administrators to review ISC's vulnerability matrix and apply applicable updates.
ISC publicly disclosed 14 BIND 9 flaws—seven high severity and seven medium severity—and released fixes in BIND 9.21.26 and 9.20.29. The issues include remotely exploitable denial-of-service flaws, cache-poisoning risks, and unauthorized insertion of zone data; ISC stated it knew of no active exploitation.
ISC revised the fixed-version information in the affected BIND 9 vulnerability advisories before their public disclosure.
ISC issued early notifications for multiple BIND 9 vulnerabilities later tracked as CVE-2026-77692, CVE-2026-19668, CVE-2026-80274, CVE-2026-19033, CVE-2026-19667, CVE-2026-19662, CVE-2026-19666, CVE-2026-78301, CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, and CVE-2026-19941.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
31 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcethehackernews.com
Open sourceacn.gov.it
Open sourcemalware.news
Open sourcetenable.com
Open sourcetenable.com
Open sourcekb.isc.org
Open sourcekb.isc.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.