As cited
Copy frozen at (site build).
vulnerabilities
ISC has disclosed fourteen vulnerabilities in BIND 9 (CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736)
Internet Systems Consortium disclosed fourteen vulnerabilities in BIND 9 on September 16, 2026, including issues involving unauthenticated IXFR deltas applied before TSIG verification, use-after-free crashes in the query cache, and other flaws. The vulnerabilities affect DNS recursive resolvers and zone transfer processes.
Why it matters: Operators of BIND 9 DNS servers must prioritize patches for these flaws, which enable zone hijacking, denial of service, and other attacks on critical DNS infrastructure.
- Source published
- First seen by Cybersecurity Tracker