#9
The Hacker News
general
September 17, 2026 at 08:00 UTC
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
By [email protected] (The Hacker News)
AI Summary
ISC released BIND 9.20.29 and 9.21.26 on September 16 to fix 14 security flaws, including an unauthenticated crash vulnerability affecting any BIND server configured with DNS-over-HTTPS — a single malformed SIG record is sufficient to kill the named process. Additionally, CVE-2026-81642 is a critical heap overflow in the DNSSEC validator in Unbound before version 1.26.1 that enables RCE via a malicious DNS zone.
Relevance score: 77.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →