chiprook
← Security
SecuritySeptember 17, 2026, 19:30

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

NLnet Labs reported a critical heap overflow in the DNSSEC validator of all versions of the Unbound DNS resolver before 1.26.1. An attacker with control over a malicious zone could cause remote code execution; the vulnerability CVE-2026-81642 is fixed in version 1.26.1.

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
#Unbound#NLnetLabs
Read next
Security

Sekoia uncovers Exvicy, a new ClickFix MaaS built on ErrTraffic code

Security

Cyberattack hits University of Munich, student data at risk

Security

TASK#STOMP Windows backdoor steals documents, Wi-Fi passwords and screenshots

Security

CVE-2026-81657 in IBM Guardium: deserialization flaw rated 9.8