ISC Patches 14 Vulnerabilities in BIND 9 Security Update
ISC releases BIND 9 security update patching 14 vulnerabilities, 7 critical, causing DoS.
Summary
Internet Systems Consortium (ISC) has released security updates for BIND, addressing 14 vulnerabilities. Seven of these are high-severity flaws that could lead to denial-of-service conditions through unexpected program exits, memory exhaustion, or termination of the named process. One critical vulnerability, CVE-2026-77692, can be exploited remotely with a single crafted DNS-over-HTTPS request.
Full text
Internet Systems Consortium (ISC) has released fresh security updates for BIND, the widely used open source DNS server software, resolving 14 vulnerabilities that could lead to denial-of-service (DoS) attacks. Seven are high-severity flaws that could be exploited to cause an unexpected program exit, memory exhaustion, named termination, and resource exhaustion, causing DoS conditions. The remotely exploitable bugs are tracked as CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736. They can be triggered using mismatched NOQNAME proof, QTYPE TKEY queries, malformed answers from the authoritative server, SVCB/HTTPS AliasMode records, crafted DNS-over-HTTPS (DoH) requests, and negative answers of 65,536 bytes. CVE-2026-77692 stands out because it can be exploited remotely without authentication to crash named with a single DoH SIG(0) request. “An attacker can cause named to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely,” ISC explains.Advertisement. Scroll to continue reading. The BIND updates also resolve seven medium-severity vulnerabilities that could lead to cache poisoning, increased memory usage of the negative cache, CPU exhaustion and packet loss, arbitrary attacker-supplied data being added to a zone, and DoS attacks. All security defects were addressed with the release of BIND versions 9.21.26 and 9.20.29. ISC says it is not aware of any of the resolved bugs being exploited in the wild, but recommends updating BIND deployments as soon as possible. Additional information is available on the BIND security advisories page and on BIND 9’s release notes page. Related: Oracle Patches 800+ Vulnerabilities in September 2026 Security Update Related: Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases Related: Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day Related: Pixel Modem Zero-Day Exploited in Targeted Attacks Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire AIUC Raises $40 Million to Certify Enterprise AI AgentsUnauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover280,000 Impacted by Premier Medical Group Data BreachChrome, Firefox Updates Patch 115 VulnerabilitiesAcronis Patches Exploited Vulnerability in cPanel Backup PluginOracle Patches 800+ Vulnerabilities in September 2026 Security UpdateExein Secures $270M at $1.7B Valuation for Physical AI SecurityThai Broadband Provider Hacked via Fortinet Vulnerability Latest News Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M RansomComp AI Raises $34 Million for AI-Native Compliance and SecurityRansomware Attacks on Manufacturers Surge as Supply Chain Risk GrowsCisco Fixes Dozens of Flaws Across FMC, ISE and Nexus DashboardCISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure DefensesAI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing RefusalsActive Exploitation Triggers Emergency Patch for Cisco ISE Zero-DayFirst Agentic AI Data Breach Reported to Spanish Regulator Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the Moveincident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.GDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-80274
- cve — CVE-2026-76163
- cve — CVE-2026-19666
- cve — CVE-2026-81563
- cve — CVE-2026-77692
- cve — CVE-2026-19667
- cve — CVE-2026-81736