Home / Sep 19, 2026 / Story
0
#4 The Hacker News general September 17, 2026 at 12:30 UTC

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

By [email protected] (The Hacker News)

AI Summary

NLnet Labs disclosed CVE-2026-81642, a critical heap overflow in the DNSSEC validator of all Unbound DNS resolver releases prior to version 1.26.1, exploitable by an attacker controlling a malicious DNS zone to achieve remote code execution on vulnerable resolvers. Unbound 1.26.1 was released simultaneously with the advisory; administrators running Unbound in production should upgrade immediately given the RCE impact on core DNS infrastructure.

Relevance score: 83.0/100

# More from September 19