ISC patches 14 vulnerabilities in BIND 9 security update
Internet Systems Consortium released BIND 9.21.26 and 9.20.29, fixing 14 vulnerabilities, seven of them high-severity and leading to denial of service. CVE-2026-77692 lets an unauthenticated remote attacker crash named with a single malformed SIG(0) DoH request.
- Seven high-severity vulnerabilities cause denial of service
- CVE-2026-77692 crashes named with one DoH SIG(0) request
- Fixes in BIND 9.21.26 and 9.20.29
- ISC has not recorded real-world exploitation
Read next
Security