CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

ISC has disclosed fourteen vulnerabilities in BIND 9 (CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7543

As cited

Copy frozen at (site build).

vulnerabilities

ISC has disclosed fourteen vulnerabilities in BIND 9 (CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736)

Internet Systems Consortium disclosed fourteen vulnerabilities in BIND 9 on September 16, 2026, including issues involving unauthenticated IXFR deltas applied before TSIG verification, use-after-free crashes in the query cache, and other flaws. The vulnerabilities affect DNS recursive resolvers and zone transfer processes.

Why it matters: Operators of BIND 9 DNS servers must prioritize patches for these flaws, which enable zone hijacking, denial of service, and other attacks on critical DNS infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary