The Internet Systems Consortium (ISC) has released security updates for BIND 9, its widely used open source DNS server software, addressing fourteen vulnerabilities affecting multiple components of the platform. The updates, released through BIND 9.20.29 and 9.21.26, include fixes for a high severity issue that could allow an unauthenticated attacker to crash a DNS server responding to DNS over HTTPS (DoH) requests. ISC disclosed the vulnerabilities on September 16 and stated that it is not aware of any active exploitation of the identified flaws.
The most notable issue is tracked as CVE-2026-77692 and affects BIND servers configured to answer DoH requests. An attacker without any credentials can send a specially crafted request containing an invalid SIG(0) signature and close the connection before the server completes signature verification. This sequence can cause the named process, which handles DNS operations in BIND, to crash. ISC has rated the vulnerability High with a CVSS 3.1 score of 7.5. Another high severity issue, CVE-2026-76163, can also trigger a crash through a TKEY query when the server configuration file does not contain a global options block. Both vulnerabilities affect the BIND 9.20 and 9.21 branches and can be triggered through direct requests without requiring an attacker-controlled DNS server.
The latest releases resolve all fourteen security issues in BIND 9.20.29, while BIND 9.21.26 addresses thirteen because CVE-2026-19662 does not impact the development branch. The Supported Preview Edition, BIND 9.20.29-S1, also includes fixes for all fourteen vulnerabilities. Twelve of the issues also affect the older BIND 9.18 branch through version 9.18.50, which has reached the end of support. ISC has advised users of unsupported versions to move to newer releases, noting that end-of-life versions should be considered vulnerable to newly discovered security issues. The vulnerabilities include several conditions that may lead to resolver crashes, denial of service, resource exhaustion, and DNS data integrity concerns. Some flaws require a recursive resolver to process specially crafted responses from an attacker-controlled server, while others involve specific configurations such as DNS64 with break-dnssec enabled, SVCB and HTTPS alias records, or DNSSEC validation scenarios.
Among the remaining vulnerabilities, several could affect how DNS data is processed or trusted by resolvers. CVE-2026-19941 and CVE-2026-77119 involve DNSSEC validation issues that could allow incorrect DNS proofs to be accepted under specific conditions, potentially resulting in cache poisoning scenarios. Another vulnerability, CVE-2026-19033, affects secondary servers using TSIG protected zone transfers and could allow unauthorized zone data to be served if a multi-message incremental transfer is interrupted before signature verification is completed. CVE-2026-78301 affects authoritative servers that load malformed zones and may cause incorrect delegation behavior or allow unintended records to enter the cache when recursion is enabled. ISC has not provided workarounds for the vulnerabilities and recommends upgrading to the latest fixed versions. The organization also noted that public reproduction tests are available to verify fixes, although they are intended for security validation rather than exploitation. The vulnerabilities were identified through a combination of ISC testing and external reports from security researchers, including Vitaly Simonovich, Rintaro Kawasugi, Samy Medjahed, Henrique Pereira, Owais Lone, and researchers from Nankai University. The latest BIND security release highlights the continued focus on strengthening DNS infrastructure against vulnerabilities affecting availability, data integrity, and server reliability.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.