ISC Patches 14 Vulnerabilities in BIND 9 Security Update
ISC has released BIND 9 versions 9.21.26 and 9.20.29 to fix 14 vulnerabilities, including seven high-severity flaws that can cause denial-of-service conditions. Remote attack paths affect CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736; CVE-2026-77692 can crash named through one unauthenticated DoH SIG(0) request. The remaining fixes address risks including cache poisoning, resource exhaustion, packet loss, and injection of attacker-controlled data into zones. ISC has not observed exploitation in the wild and recommends updating deployments promptly.