BIND 9 Security Flaws Allow Attackers to Bypass Security Controls and Crash Servers
ID: 2892362f-7eca-5230-9c26-93158069e171
STIX ID: report--2892362f-7eca-5230-9c26-93158069e171
Feed Name: GBHackers
Threat Score
ISC disclosed three vulnerabilities in BIND 9 — CVE-2026-1519 (high, DoS via excessive NSEC3 iterations), CVE-2026-3119 (medium, named crash via TKEY with valid TSIG), and CVE-2026-3591 (medium, SIG(0) stack use-after-return enabling ACL bypass). Affected BIND 9 branches and CVSS scores are provided; ISC recommends immediate patching to versions 9.18.47, 9.20.21, or 9.21.20 and removal of unnecessary/compromised TSIG keys where applicable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
