BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
ID: 8715ad49-d987-5073-a6a0-83b0e8bc2e38
STIX ID: report--8715ad49-d987-5073-a6a0-83b0e8bc2e38
Feed Name: CosmicBytez Labs
ISC released fixes for 14 vulnerabilities in BIND 9 (September 2026), including multiple High-severity flaws — notably CVE-2026-77692, which allows an unauthenticated, single-request DNS-over-HTTPS (DoH) crash of the named process. Affected branches include 9.20 and 9.21 (and Supported Preview builds); ISC recommends immediate upgrades to 9.20.29/9.21.26 (or vendor backports) and disabling DoH if unused. ISC reported no known active exploitation at disclosure, but the pre-auth, single-request DoS and cache-poisoning risks pose significant availability and integrity concerns for widely deployed resolvers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
