logo

706,000+ BIND 9 Resolver Instances Vulnerable to Cache Poisoning Exposed Online – PoC Released

ID: b2cf106f-f55e-5d7b-8a5d-2edeb31d50a9

STIX ID: report--b2cf106f-f55e-5d7b-8a5d-2edeb31d50a9

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-10-26

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A critical logic flaw in BIND 9 resolvers (CVE-2025-40778, CVSS 8.6) allows off‑path attackers to inject unsolicited resource records and poison resolver caches, potentially redirecting traffic; over 706,000 exposed instances were identified and a public PoC exists, so ISC urges immediate patching or temporary mitigations such as restricting recursion and enabling DNSSEC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.