ISC Patches 14 Vulnerabilities in BIND 9 Security Update
The Internet Systems Consortium (ISC) released security updates for BIND 9 to address 14 vulnerabilities, including seven high-severity flaws that can cause denial-of-service (DoS) conditions by triggering unexpected program exits, memory exhaustion, or termination of the named process. These vulnerabilities can be exploited remotely through various crafted DNS queries and DNS-over-HTTPS (DoH) requests, including one that allows unauthenticated remote crash of named with a single DoH SIG(0) request. Seven additional medium-severity vulnerabilities address issues such as cache poisoning, increased memory usage, CPU exhaustion, and arbitrary data injection. ISC has released fixed versions 9.21.26 and 9.20.29 to resolve these issues and recommends prompt updating. No active exploitation in the wild is currently known.
AI Analysis
Technical Summary
ISC patched 14 vulnerabilities in BIND 9, a widely used open source DNS server. Seven high-severity flaws can be remotely exploited to cause denial-of-service by crashing the named process or exhausting resources. Notably, CVE-2026-77692 allows unauthenticated remote crash via a crafted DNS-over-HTTPS SIG(0) request. Other vulnerabilities involve malformed DNS queries and responses, including NOQNAME proof mismatches, QTYPE TKEY queries, malformed authoritative answers, SVCB/HTTPS AliasMode records, and large negative answers. Seven medium-severity issues include cache poisoning, increased negative cache memory usage, CPU exhaustion, packet loss, and arbitrary data injection into zones. ISC released BIND versions 9.21.26 and 9.20.29 to fix all these vulnerabilities. ISC is not aware of exploitation in the wild but urges immediate updates.
Potential Impact
Successful exploitation of these vulnerabilities can lead to denial-of-service conditions by causing the named DNS server process to crash or exhaust system resources such as memory and CPU. One vulnerability (CVE-2026-77692) can be triggered remotely without authentication, allowing an attacker to crash the DNS server with a single specially crafted DNS-over-HTTPS request. Other vulnerabilities may enable cache poisoning, increased memory usage, CPU exhaustion, packet loss, and injection of arbitrary attacker-supplied data into DNS zones, potentially impacting DNS reliability and integrity.
Mitigation Recommendations
ISC has released official security updates in BIND versions 9.21.26 and 9.20.29 that address all 14 vulnerabilities. Administrators should update their BIND deployments to these versions as soon as possible to mitigate the risks. ISC is not aware of any active exploitation of these vulnerabilities in the wild. No additional mitigations beyond applying the official patches are indicated by the vendor.
ISC Patches 14 Vulnerabilities in BIND 9 Security Update
Description
The Internet Systems Consortium (ISC) released security updates for BIND 9 to address 14 vulnerabilities, including seven high-severity flaws that can cause denial-of-service (DoS) conditions by triggering unexpected program exits, memory exhaustion, or termination of the named process. These vulnerabilities can be exploited remotely through various crafted DNS queries and DNS-over-HTTPS (DoH) requests, including one that allows unauthenticated remote crash of named with a single DoH SIG(0) request. Seven additional medium-severity vulnerabilities address issues such as cache poisoning, increased memory usage, CPU exhaustion, and arbitrary data injection. ISC has released fixed versions 9.21.26 and 9.20.29 to resolve these issues and recommends prompt updating. No active exploitation in the wild is currently known.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ISC patched 14 vulnerabilities in BIND 9, a widely used open source DNS server. Seven high-severity flaws can be remotely exploited to cause denial-of-service by crashing the named process or exhausting resources. Notably, CVE-2026-77692 allows unauthenticated remote crash via a crafted DNS-over-HTTPS SIG(0) request. Other vulnerabilities involve malformed DNS queries and responses, including NOQNAME proof mismatches, QTYPE TKEY queries, malformed authoritative answers, SVCB/HTTPS AliasMode records, and large negative answers. Seven medium-severity issues include cache poisoning, increased negative cache memory usage, CPU exhaustion, packet loss, and arbitrary data injection into zones. ISC released BIND versions 9.21.26 and 9.20.29 to fix all these vulnerabilities. ISC is not aware of exploitation in the wild but urges immediate updates.
Potential Impact
Successful exploitation of these vulnerabilities can lead to denial-of-service conditions by causing the named DNS server process to crash or exhaust system resources such as memory and CPU. One vulnerability (CVE-2026-77692) can be triggered remotely without authentication, allowing an attacker to crash the DNS server with a single specially crafted DNS-over-HTTPS request. Other vulnerabilities may enable cache poisoning, increased memory usage, CPU exhaustion, packet loss, and injection of arbitrary attacker-supplied data into DNS zones, potentially impacting DNS reliability and integrity.
Mitigation Recommendations
ISC has released official security updates in BIND versions 9.21.26 and 9.20.29 that address all 14 vulnerabilities. Administrators should update their BIND deployments to these versions as soon as possible to mitigate the risks. ISC is not aware of any active exploitation of these vulnerabilities in the wild. No additional mitigations beyond applying the official patches are indicated by the vendor.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/","fetched":true,"fetchedAt":"2026-09-17T12:46:37.144Z","wordCount":931}
Threat ID: 6aabe12d55bf5e2cf5633e19
Added to database: 09/17/2026, 12:46:37 UTC
Last enriched: 09/17/2026, 12:46:43 UTC
Last updated: 09/17/2026, 20:48:37 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.