Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2898+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. ISC Patches 14 Vulnerabilities in BIND 9 DNS Server Software
ISC Patches 14 Vulnerabilities in BIND 9 DNS Server Software
NEWS

ISC Patches 14 Vulnerabilities in BIND 9 DNS Server Software

ISC fixes 14 BIND 9 flaws, including 7 high-severity bugs that can crash named, exhaust memory, or poison DNS caches. No active exploitation reported.

Dylan H.

News Desk

September 18, 2026
2 min read

14 Flaws, Seven Rated High Severity

The Internet Systems Consortium (ISC) has released a security update for BIND 9, the most widely deployed open-source DNS server software, patching 14 vulnerabilities. Seven are rated high severity and seven medium severity. ISC reports no evidence of active exploitation for any of them, but recommends deploying the fixes promptly given BIND's foundational role in internet infrastructure.


High-Severity Flaws

The high-severity issues are remotely exploitable and can cause unexpected program termination, memory depletion, or denial-of-service conditions in the named daemon:

  • CVE-2026-80274
  • CVE-2026-76163
  • CVE-2026-19666
  • CVE-2026-81563
  • CVE-2026-77692
  • CVE-2026-19667
  • CVE-2026-81736

One flaw, CVE-2026-77692, stands out for its exploitation path: an attacker can cause named to abort by sending a crafted DNS-over-HTTPS (DoH) request containing a cryptographically invalid SIG(0) record, then prematurely closing the transport connection before the server finishes processing it.


Medium-Severity Flaws

The seven medium-severity issues cover a different class of impact — rather than outright crashing the resolver, they can enable:

  • Cache poisoning
  • CPU exhaustion
  • Packet loss
  • Unauthorized data injection into zones

These are generally harder to weaponize for immediate disruption but can be chained with other techniques to degrade DNS integrity or availability over time.


Patched Versions

ISC has shipped fixes in:

  • BIND 9.21.26
  • BIND 9.20.29

Administrators running earlier 9.20.x or 9.21.x branches — or any BIND 9 deployment providing authoritative or recursive DNS service — should plan an upgrade. Given BIND's position as core internet infrastructure sitting on the critical path for name resolution, denial-of-service bugs against named carry outsized blast radius, particularly for ISPs, hosting providers, and enterprises running their own recursive resolvers.

Full technical details for each CVE are available in ISC's security advisories and the BIND 9 release notes.

Sources

  • SecurityWeek — ISC Patches 14 Vulnerabilities in BIND 9 Security Update
#BIND 9#ISC#DNS#Denial of Service#Security Updates#Vulnerability

Related Articles

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

ISC's BIND 9.20.29 and 9.21.26 fix 14 flaws, including an unauthenticated DoH request that can crash the named process.

5 min read

Microsoft Patches 138 Vulnerabilities Including DNS and Netlogon RCE Flaws

Microsoft's May 2026 Patch Tuesday addresses 138 security vulnerabilities across its product portfolio, including 30 rated Critical — with notable DNS...

6 min read

CVE-2026-28872: Apple iOS & iPadOS Remote Denial-of-Service

A CVSS 7.5 denial-of-service vulnerability in Apple iOS and iPadOS allows a remote attacker to exhaust device resources and crash the operating system...

5 min read
Back to all News