Patch released Unbound rce NLnet Labs
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
CVE Tools coverage
NLnet Labs released Unbound 1.26.1 to address CVE-2026-81642, a DNSSEC validator heap overflow affecting versions through 1.26.0 that a malicious DNS zone could use to cause denial of service or potentially execute code remotely. The update also fixes CVE-2026-82717, CVE-2026-81634, CVE-2026-77955, CVE-2026-78227, CVE-2026-80225, CVE-2026-82720, CVE-2026-85501, and CVE-2026-77860. Neither CVE-2026-81642 nor CVE-2026-82717 is known to be exploited, but operators should upgrade to Unbound 1.26.1 or apply the available patches.