#4
The Hacker News
general
September 17, 2026 at 12:30 UTC
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
By [email protected] (The Hacker News)
AI Summary
NLnet Labs disclosed CVE-2026-81642, a critical heap overflow in the DNSSEC validator of all Unbound DNS resolver releases prior to version 1.26.1, exploitable by an attacker controlling a malicious DNS zone to achieve remote code execution on vulnerable resolvers. Unbound 1.26.1 was released simultaneously with the advisory; administrators running Unbound in production should upgrade immediately given the RCE impact on core DNS infrastructure.
Relevance score: 83.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →