BIND 9 Security Alert: ISC Releases Patches for Trio of Vulnerabilities
ID: 8484898b-8a7d-5023-a807-fb6ffabbbd0c
STIX ID: report--8484898b-8a7d-5023-a807-fb6ffabbbd0c
Feed Name: securityonline.info
The Internet Systems Consortium published a security advisory for BIND 9 describing three vulnerabilities—CVE-2026-3591 (ACL bypass via SIG(0) signed queries), CVE-2026-1519 (resolver CPU exhaustion/DoS via excessive NSEC3 iterations during DNSSEC validation), and CVE-2026-3119 (named crash when processing a correctly signed TKEY requiring a known TSIG). Affected versions and patched releases are listed; ISC advises upgrading to the nearest patched release and provides temporary mitigations such as removing unnecessary TSIG keys or disabling DNSSEC validation (the latter not recommended).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
