Red Hat, AlmaLinux, Rocky Linux, and Oracle Linux issued Unbound updates for CVE-2026-50252, a DNS cache-poisoning flaw caused by predictable UDP source ports. The issue can be exploited from an adjacent network and has high integrity and availability impact; affected enterprise Linux packages include Unbound libraries, development packages, dracut components, and Python bindings. Red Hat provides unbound-1.24.2-7.el10_2.5 for supported RHEL 10 and 10.2 deployments across x86_64, ARM64, s390x, and ppc64le, while corresponding downstream advisories cover AlmaLinux, Rocky Linux 9/10, and Oracle Linux 9. No public exploitation has been reported.
Separately, NLnet Labs released Unbound 1.26.1 to fix nine vulnerabilities in upstream versions through 1.26.0, including critical DNSSEC validator heap overflow CVE-2026-81642. A malicious DNS-zone operator could trigger the flaw when a vulnerable resolver processes queries for the zone, causing denial of service and potentially remote code execution; CVE-2026-82717 is a second heap-corruption issue that may permit RCE in certain builds. Administrators should promptly apply their distribution’s security updates and upgrade upstream-managed Unbound deployments to 1.26.1 or use vendor source patches where immediate upgrades are not feasible.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Rocky Linux published security patches for Rocky Linux 9 and Rocky Linux 10 Unbound packages to address CVE-2026-50252.
An AlmaLinux 10 security update associated with RHSA-2026:68291 became available for affected Unbound-related packages across AlmaLinux repositories and variants.
Oracle published a security update for Oracle Linux 9 Unbound packages to remediate CVE-2026-50252.
Red Hat published Moderate-severity advisory RHSA-2026:68291 for RHEL 10, supplying Unbound 1.24.2-7.el10_2.5 packages that remediate CVE-2026-50252. The update covers supported RHEL 10 architectures and associated CodeReady Linux Builder repositories.
The reporter verified NLnet Labs' patch for CVE-2026-81642.
NLnet Labs provided a patch for the critical Unbound DNSSEC-validator heap-overflow vulnerability CVE-2026-81642.
Yuqi Qiu, who found the issue with Xiang Li of Nankai University's AOSP Lab, reported CVE-2026-81642 to NLnet Labs. The flaw is a DNSSEC-validator heap overflow triggerable by an operator of a malicious DNS zone.
CVE-2026-50252, affecting Unbound packages and enabling DNS cache poisoning through predictable UDP source ports, was published. The issue has adjacent-network attack requirements and high integrity and availability impacts.
NLnet Labs released Unbound 1.26.1 to remediate nine vulnerabilities affecting releases through 1.26.0, including critical CVE-2026-81642 and heap-corruption flaw CVE-2026-82717. The release also addressed multiple denial-of-service and service-degradation flaws, and changed the default for val-clean-additional to off as part of the ReTrap remediation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourcenlnetlabs.nl
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.