Back to advisories

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

ISC released BIND 9.20.29 and 9.21.26 on September 16 to patch 14 vulnerabilities, including a critical unauthenticated DoH crash flaw. A single malformed DNS-over-HTTPS request with an invalid SIG(0) signature can take down BIND servers. Seven additional High severity flaws enable denial-of-service attacks, with seven Medium severity issues affecting DNS data integrity and DNSSEC validation.

HIGHAdvisorySep 18, 2026
Action required
Immediately identify all BIND 9 instances in your environment. Prioritize patching to 9.20.29 or 9.21.26 within 48 hours. In parallel, enable DoH request logging and monitor for malformed SIG(0) signature patterns as a detection control.
Affected products
BIND 9Internet Systems Consortium