Skip to main content

ISC Patches 14 Vulnerabilities in BIND 9 Security Update

0
High
Vulnerability
Published: 09/17/2026 (09/17/2026, 12:39:28 UTC)
Source: SecurityWeek

Description

The Internet Systems Consortium (ISC) released security updates for BIND 9 to address 14 vulnerabilities, including seven high-severity flaws that can cause denial-of-service (DoS) conditions by triggering unexpected program exits, memory exhaustion, or termination of the named process. These vulnerabilities can be exploited remotely through various crafted DNS queries and DNS-over-HTTPS (DoH) requests, including one that allows unauthenticated remote crash of named with a single DoH SIG(0) request. Seven additional medium-severity vulnerabilities address issues such as cache poisoning, increased memory usage, CPU exhaustion, and arbitrary data injection. ISC has released fixed versions 9.21.26 and 9.20.29 to resolve these issues and recommends prompt updating. No active exploitation in the wild is currently known.

Affected software

Affected versions
<9.21.26<9.20.29

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 12:46:43 UTC

Technical Analysis

ISC patched 14 vulnerabilities in BIND 9, a widely used open source DNS server. Seven high-severity flaws can be remotely exploited to cause denial-of-service by crashing the named process or exhausting resources. Notably, CVE-2026-77692 allows unauthenticated remote crash via a crafted DNS-over-HTTPS SIG(0) request. Other vulnerabilities involve malformed DNS queries and responses, including NOQNAME proof mismatches, QTYPE TKEY queries, malformed authoritative answers, SVCB/HTTPS AliasMode records, and large negative answers. Seven medium-severity issues include cache poisoning, increased negative cache memory usage, CPU exhaustion, packet loss, and arbitrary data injection into zones. ISC released BIND versions 9.21.26 and 9.20.29 to fix all these vulnerabilities. ISC is not aware of exploitation in the wild but urges immediate updates.

Potential Impact

Successful exploitation of these vulnerabilities can lead to denial-of-service conditions by causing the named DNS server process to crash or exhaust system resources such as memory and CPU. One vulnerability (CVE-2026-77692) can be triggered remotely without authentication, allowing an attacker to crash the DNS server with a single specially crafted DNS-over-HTTPS request. Other vulnerabilities may enable cache poisoning, increased memory usage, CPU exhaustion, packet loss, and injection of arbitrary attacker-supplied data into DNS zones, potentially impacting DNS reliability and integrity.

Mitigation Recommendations

ISC has released official security updates in BIND versions 9.21.26 and 9.20.29 that address all 14 vulnerabilities. Administrators should update their BIND deployments to these versions as soon as possible to mitigate the risks. ISC is not aware of any active exploitation of these vulnerabilities in the wild. No additional mitigations beyond applying the official patches are indicated by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/","fetched":true,"fetchedAt":"2026-09-17T12:46:37.144Z","wordCount":931}

Threat ID: 6aabe12d55bf5e2cf5633e19

Added to database: 09/17/2026, 12:46:37 UTC

Last enriched: 09/17/2026, 12:46:43 UTC

Last updated: 09/17/2026, 20:48:37 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses