ISC Patches BIND 9 Vulnerabilities That Could Affect DNS Service Availability and Data Integrity

Views: 71 views

516/69 Friday, September 18, 2026

Internet Systems Consortium (ISC) has released security updates for BIND 9 to address 14 vulnerabilities covering issues that may affect the availability and integrity of DNS services. Some of the vulnerabilities can be exploited without authentication and may cause the named process to crash or consume excessive system resources, resulting in a denial-of-service (DoS) condition. ISC stated in its advisories that it has not observed evidence of these vulnerabilities being exploited in the wild.

The fixed vulnerabilities have different conditions and impacts. For example, CVE-2026-81736, rated High with a CVSS score of 7.5, could cause a DNS resolver to consume excessive CPU resources and lead to DoS. CVE-2026-81563, also rated High, could cause memory usage to increase continuously until the system can no longer process new recursive queries. Other vulnerabilities may cause named to crash or affect DNS data processing and the accuracy of information used by resolvers or DNS servers.

Administrators using BIND 9 should check their deployed versions and update to BIND 9.20.29 or 9.21.26, depending on the release branch in use. Organizations still using BIND 9.18 should plan to upgrade to a supported version, as BIND 9.18 has reached end of support and will not receive patches for this set of vulnerabilities. Administrators should also review ISC’s advisory for each CVE to assess whether their configurations and deployment models meet the conditions affected by the vulnerabilities.

Source: https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/