Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-13204: CWE-617 Reachable Assertion in ISC BIND 9CVE-2026-13204
0

CVE-2026-13204 is a vulnerability in ISC BIND 9 where the software may exit unexpectedly due to an assertion failure during DNSSEC validation. This occurs if a provably insecure domain is covered by both NSEC and NSEC3 records at the parent zone, but an RRSIG exists for only one of these record types. The issue affects multiple BIND 9 versions including 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and their respective S1 variants. The vulnerability has a high severity with a CVSS score of 7.5 and impacts availability by causing the DNS server to exit unexpectedly.

Join the discussion
CVE-2026-12617: CWE-617 Reachable Assertion in ISC BIND 9CVE-2026-12617
0

CVE-2026-12617 is a vulnerability in ISC BIND 9 that causes unexpected program termination (crash) due to reachable assertions triggered by specific query response ordering and content involving CNAME, DNAME, and A records. The issue affects multiple BIND 9 versions and can cause the named DNS server process to quit unexpectedly.

Join the discussion
CVE-2026-11721: CWE-1284 Improper Validation of Specified Quantity in Input in ISC BIND 9CVE-2026-11721
0

A vulnerability in ISC BIND 9 allows an attacker controlling a DNS zone to respond with an RRSIG containing fewer labels than the zone, causing the DNS server to generate a wildcard name for a shorter zone. This can lead to cache poisoning if the resolver has 'synth-from-dnssec' enabled, which is the default setting. The issue affects multiple BIND 9 versions from 9.11.0 through 9.21.23 and their respective S1 variants.

Join the discussion
CVE-2026-11622: CWE-770 Allocation of Resources Without Limits or Throttling in ISC BIND 9CVE-2026-11622
0

CVE-2026-11622 is a high-severity vulnerability in ISC BIND 9 DNSSEC validating resolvers. Under a random subdomain attack against a DNSSEC-signed zone, the resolver can experience runaway memory usage that far exceeds configured cache limits. This occurs when an attacker sends queries faster than the resolver can validate them. The issue affects multiple BIND 9 versions including 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and their respective S1 variants.

Join the discussion
CVE-2026-11605: CWE-408 Incorrect Behavior Order - Early Amplification in ISC BIND 9CVE-2026-11605
0

CVE-2026-11605 is a resource exhaustion vulnerability in ISC BIND 9 DNS server software related to DNSSEC validation. The issue arises because BIND 9 validates all RRSIG records in a DNS response, even when some are unnecessary. This can cause excessive CPU usage when querying authoritative servers that return many valid but superfluous RRSIG records. The vulnerability affects specific versions of BIND 9, including 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1. It has a high severity score of 7.5 but no known exploits in the wild. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion
CVE-2026-11331: CWE-790 Improper Filtering of Special Elements in ISC BIND 9CVE-2026-11331
0

CVE-2026-11331 is a vulnerability in ISC BIND 9 affecting versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and certain S1 variants. It involves improper handling of NAMETOOLONG errors during Response Policy Zone (RPZ) processing with wildcard CNAME policies. An attacker can craft long query names to trigger this error, potentially bypassing RPZ rules or causing the BIND 9 software to exit unexpectedly.

Join the discussion
CVE-2026-10822: CWE-617 Reachable Assertion in ISC BIND 9CVE-2026-10822
0

A reachable assertion vulnerability exists in ISC BIND 9 when processing DNS records with a PRIVATEDNS algorithm (253) that specify an invalid length longer than the actual identifier data. This causes BIND to store invalid data and potentially abort when rendering the record to text. The issue affects multiple BIND 9 versions including 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, and 9.21.0 through 9.21.23, including some S1 variants.

Join the discussion
CVE-2026-10723: CWE-347 Improper Verification of Cryptographic Signature in ISC BIND 9CVE-2026-10723
0

A vulnerability in ISC BIND 9 allows acceptance of incorrect child-zone NSEC3 records as valid, potentially enabling attackers to forge authenticated NXDOMAIN responses. This affects multiple BIND 9 versions including 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and certain S1 variants. The issue is classified as CWE-347, improper verification of cryptographic signature. The CVSS score is 6.8, indicating a medium severity level.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:github/isc/bind9
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses