The Internet Systems Consortium (ISC) has released security updates for BIND 9, its open-source DNS server software. The updates, BIND 9.20.29 and 9.21.26, address fourteen security vulnerabilities that were disclosed on September 16.
Among the fourteen flaws, one critical vulnerability, tracked as CVE-2026-77692, affects BIND servers configured to answer DNS-over-HTTPS (DoH). This flaw allows an unauthenticated attacker to crash the server process, named, with a single crafted DoH request. The attack involves sending a request with an invalid SIG(0) signature and then closing the connection prematurely before the server finishes checking the signature.
Seven of the fourteen vulnerabilities are classified as high-severity, potentially leading to denial-of-service (DoS) conditions through unexpected program exits, memory exhaustion, or resource exhaustion. These can be triggered by various methods, including mismatched NOQNAME proof, QTYPE TKEY queries, malformed answers, SVCB/HTTPS AliasMode records, crafted DoH requests, and negative answers of 65,536 bytes. The remaining seven vulnerabilities are of medium severity.
BIND 9.20.29, on the current stable branch, fixes all fourteen vulnerabilities. BIND 9.21.26, on the development branch, fixes thirteen, as CVE-2026-19662 does not affect version 9.21. A supported preview edition, BIND 9.20.29-S1, also fixes all fourteen. Twelve of the fourteen flaws also impact the older 9.18 branch, up to and including 9.18.50, for which ISC ended support at the end of June and has not released fixes. ISC has not identified any workarounds for these vulnerabilities and is not aware of any active exploitation.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Internet Systems Consortium (ISC) released security updates for BIND, its open-source DNS server software, addressing 14 vulnerabilities, including seven high-severity flaws. These vulnerabilities could lead to denial-of-service attacks and other issues, prompting ISC to recommend immediate updates for BIND deployments.
The Internet Systems Consortium (ISC) released BIND 9.20.29 and 9.21.26 to address fourteen security vulnerabilities in its open-source DNS server software. One critical flaw allows an unauthenticated attacker to crash a BIND server configured for DNS-over-HTTPS (DoH) with a single request. These updates are important for maintaining the stability and security of DNS infrastructure globally.