[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:bind-9-update-fixes-14-flaws-including-an-unauthenticated-crash-over-dns-over-ht-mu6dm852":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":15,"article_ids":16,"ioc_summary":18,"source_urls":19,"status":21,"expires_at":22,"created_at":23,"updated_at":24,"articles":25},"8bd93859-66cb-4e9c-95de-2ae30f408193","BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS","bind-9-update-fixes-14-flaws-including-an-unauthenticated-crash-over-dns-over-ht-mu6dm852","ISC released BIND 9.20.29 and 9.21.26 on September 16 to patch 14 vulnerabilities, including a critical unauthenticated DoH crash flaw. A single malformed DNS-over-HTTPS request with an invalid SIG(0) signature can take down BIND servers. Seven additional High severity flaws enable denial-of-service attacks, with seven Medium severity issues affecting DNS data integrity and DNSSEC validation.","high","advisory",[],[13,14],"BIND 9","Internet Systems Consortium","Immediately identify all BIND 9 instances in your environment. Prioritize patching to 9.20.29 or 9.21.26 within 48 hours. In parallel, enable DoH request logging and monitor for malformed SIG(0) signature patterns as a detection control.",[17],"98483035-e602-4508-a78d-04f8fe2a2614",null,[20],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fbind-9-update-fixes-14-flaws-including.html","active","2026-09-20T03:05:46.728+00:00","2026-09-18T03:05:49.31977+00:00","2026-09-18T03:05:52.679482+00:00",[26],{"id":17,"title":6,"url":20}]