Overview
An 11-year-old denial-of-service flaw in ISC BIND, the most widely deployed DNS server software on the internet, was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on October 8, 2026, with a federal remediation deadline of October 11, 2026. Tracked as CVE-2015-5477, the bug is a data processing / reachable assertion error in how named — BIND's core server daemon — handles TKEY resource records, letting a remote attacker crash the process with a single crafted DNS query.
The flaw was originally disclosed by ISC in July 2015 and carries a CVSS v2 score of 7.8, scored by CISA in this KEV addition at 7.5. It is being treated as a High severity issue on the Labs scale. What makes a decade-old bug newsworthy in 2026 is the reason it was added now: CISA ties its addition to active exploitation by Flax Typhoon (also tracked as RedJuliett and Ethereal Panda), the China-linked group behind the Integrity Technology Group stolen-email-access portal exposed in a joint FBI/CISA/NSA advisory the same week. CVE-2015-5477 was one of five newly KEV-listed flaws — alongside bugs in ProFTPD, ONLYOFFICE Docs, Strapi, and Apache Struts — out of eight total vulnerabilities the advisory says Flax Typhoon's operators have used for initial access and data exfiltration.
Technical Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2015-5477 |
| Severity | High |
| CVSS v2 Score | 7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C) |
| CVSS Score (per CISA KEV, Oct 2026) | 7.5 |
| CWE Class | Reachable Assertion / Data Processing Errors |
| Vendor / Project | Internet Systems Consortium (ISC) / BIND |
| Vulnerable Component | named daemon — TKEY resource record handling |
| Affected Versions | BIND 9.1.0 through 9.9.7-P1 (≤ 9.9.7-P1); BIND 9.10.0 through 9.10.2-P2 (≤ 9.10.2-P2) |
| Fixed Versions | BIND 9.9.7-P2 or BIND 9.10.2-P3 and later |
| Attack Vector | Network, low complexity, no authentication, no user interaction |
| Date Added to CISA KEV | October 8, 2026 |
| Federal Remediation Due | October 11, 2026 |
| Exploit Status | Confirmed exploited in the wild (Flax Typhoon); public Metasploit module and proof-of-concept exploits available |
| Original Disclosure | July 28, 2015 (ISC Knowledge Base AA-01272) |
How It Works
TKEY records are a BIND mechanism for negotiating shared transaction keys used in dynamic DNS updates. ISC's original advisory describes the root cause as an error in how named validates incoming TKEY queries: a specially crafted record can trip a REQUIRE assertion deep in BIND's packet-handling code, which the software treats as an unrecoverable internal-consistency failure and responds to by terminating the process outright.
Two details made this bug unusually severe even in 2015, and still relevant today:
- Both authoritative and recursive servers are vulnerable — the flaw sits in generic packet-parsing logic exercised by any
namedinstance that accepts DNS queries, not a feature limited to one server role. - Access controls do not help. The vulnerable code path executes before BIND evaluates ACLs or other configuration options meant to restrict who can query the server, so firewalling query access down to trusted hosts does not prevent an attacker who can reach port 53 at all from crashing the daemon.
A single malformed TKEY query is sufficient — there is no need for an ongoing flood, amplification, or spoofing technique. Each successful crash simply takes the resolver or authoritative server offline until something restarts it, making this a textbook crash-and-repeat denial-of-service primitive.
Why a 2015 Bug Matters in 2026
CVE-2015-5477 has had a patch available for over a decade, and the only reason it is appearing in a 2026 advisory is that unpatched BIND installations still exist in the wild and are being targeted by a capable, patient adversary. CISA's joint advisory links this specific KEV addition to Flax Typhoon's broader campaign against government, healthcare, critical-manufacturing, and education targets across Southeast Asia and beyond — the same operation tied to the Integrity Technology Group portal that gave third parties access to archived stolen email. Legacy, internet-facing DNS infrastructure that was never upgraded past BIND 9.10.2-P2 is exactly the kind of soft target that lets a state-aligned actor achieve easy, repeatable disruption without burning a zero-day.
This is a useful reminder for defenders: KEV additions are not limited to recently disclosed CVEs. An old, "already fixed" bug can resurface as a live threat the moment adversaries find organizations that never applied the patch.
Recommendations
- Identify every BIND installation in your environment — including appliances, embedded network gear, and legacy Linux servers — and check the
namedversion against the affected ranges above. - Upgrade immediately to BIND 9.9.7-P2, BIND 9.10.2-P3, or any later maintained release. There is no configuration-level workaround; ACLs and query restrictions do not block this attack.
- Federal agencies subject to CISA Binding Operational Directives must remediate per BOD 22-01 by the October 11, 2026 KEV deadline.
- Monitor for unexpected
namedprocess restarts or crashes, which can indicate active exploitation attempts even if the service recovers automatically. - Treat this as part of the broader Flax Typhoon advisory — organizations in government, healthcare, critical manufacturing, IT, and education sectors should review the full eight-vulnerability list in the joint FBI/CISA/NSA advisory, not just this single CVE.
Key Takeaways
- CVE-2015-5477 is an 11-year-old reachable-assertion denial-of-service flaw in ISC BIND's TKEY query handling, newly added to CISA's KEV catalog on October 8, 2026.
- A single crafted DNS query crashes
namedon both authoritative and recursive servers; ACLs do not mitigate it because the flaw triggers before access-control checks run. - The addition is tied to active exploitation by Flax Typhoon (RedJuliett / Ethereal Panda), the China-linked group behind the Integrity Technology Group stolen-email-access operation disclosed the same week.
- Federal agencies face an October 11, 2026 remediation deadline; all organizations running BIND 9.10.2-P2 or earlier (or 9.9.7-P1 or earlier) should patch immediately.
- The fix — BIND 9.9.7-P2 / 9.10.2-P3 or later — has existed since 2015. This is a patching-hygiene failure being actively exploited, not a new zero-day.
Sources
- CISA — Known Exploited Vulnerabilities Catalog
- ISC Knowledge Base — AA-01272: CVE-2015-5477
- The Hacker News — Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
CosmicBytez Labs will update this advisory if further detail emerges on the specific exploitation activity tied to this KEV addition.