CERT-In flags 14 ISC BIND flaws enabling cache poisoning and zone injection
CERT-In published advisory CIVN-2026-0467 on 21 September 2026 with a HIGH severity rating, covering 14 ISC BIND CVEs that allow spoofing, cache poisoning and unauthorized addition of data to a DNS zone. Affected releases include BIND 9.11.0–9.18.50, 9.20.0–9.20.27, 9.21.0–9.21.25 and the Supported Preview Edition. No active exploitation has been reported.
- Advisory CIVN-2026-0467 covers 14 CVEs in ISC BIND
- Flaws allow spoofing, cache poisoning and zone data injection
- Affected: BIND 9.11.0–9.18.50, 9.20.0–9.20.27, 9.21.0–9.21.25
- ZoomEye found 19,364,144 internet-reachable BIND hosts
Read next
Security