logo

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

ID: 4e7d96d4-9196-51fb-a326-b7a2e9d7e541

STIX ID: report--4e7d96d4-9196-51fb-a326-b7a2e9d7e541

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-09-17

Date Updated: 2026-09-18

...
...

NLnet Labs disclosed a critical heap buffer overflow (CVE-2026-81642, CVSS 9.1) in Unbound's DNSSEC validator that can be triggered remotely by specially crafted DNSKEY records; all releases through 1.26.0 are affected and the issue was fixed in Unbound 1.26.1 (released September 17, 2026). The advisory includes technical details, standalone patches and mitigation guidance; no public reports of exploitation were observed at the time of disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.