Vulnerability
Published 2026-09-16
Verified 2026-09-19

ISC BIND 9: 14 DoS flaws (7 high); fix 9.21.26 / 9.20.29 — CVE-2026-77692 unauth DoH crash

ISC published BIND 9 security advisories dated 16 September 2026 covering 14 denial-of-service vulnerabilities (SecurityWeek: seven high-severity). High CVEs include CVE-2026-80274, CVE-2026-76163, CVE-2026-19666 (use-after-free in query_addnoqnameproof() via DNS64 filter64; ISC CVSS 7.5, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), CVE-2026-81563, CVE-2026-77692 (unauthenticated remote named crash via a single crafted DoH SIG(0) request then premature connection close; ISC CVSS 7.5), CVE-2026-19667, and CVE-2026-81736. Triggers include mismatched NOQNAME proof, QTYPE TKEY queries, malformed authoritative answers, SVCB/HTTPS AliasMode records, crafted DoH, and oversized negative answers. ISC states it is not aware of exploitation of the resolved bugs. Fixed builds: BIND 9.21.26 and 9.20.29 (per SecurityWeek quoting ISC). Primary: ISC KB advisories; wire: SecurityWeek 17 Sep 2026.

Product
ISC BIND 9 (named DNS server)
Versions
Affected lines prior to fixed releases; fixed: BIND 9.21.26 and 9.20.29 (SecurityWeek / ISC)
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade BIND to 9.21.26 or 9.20.29 (or later supported fixed builds); prioritise DoH-exposed resolvers for CVE-2026-77692

Primary: ISC KB — all BIND advisories (incl. 16 Sep 2026 set) · Vendor: ISC — CVE-2026-77692 (unauth DoH SIG(0) named crash) · CVE: CVE-2026-77692, CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-19667, CVE-2026-81736 · SecurityWeek — ISC BIND 9 14 DoS flaws (17 Sep 2026)

vulnerabilities network