CERT-In Flags 14 High-Severity ISC BIND Vulnerabilities Across Multiple Releases
India's CERT-In issued advisory CIVN-2026-0467 on 21 September 2026, identifying 14 high-severity vulnerabilities in ISC BIND across a wide range of versions from 9.11.0 through 9.21.25. The flaws span three weakness categories: memory-safety issues that can crash resolvers, resource-consumption bugs that degrade performance, and trust-boundary flaws that may cause DNS servers to return incorrect answers. No active exploitation of any of the 14 CVEs has been reported by CERT-In at this time. Affected operators are advised to update to fixed builds listed in ISC's official advisory index and to restrict resolver exposure by limiting recursion, requiring TSIG for transfers, and rate-limiting DNS-over-HTTPS. With over 19 million internet-facing assets fingerprinted as ISC BIND by ZoomEye, the potential attack surface is considered significant.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in