BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
ISC has released BIND 9.20.29 and 9.21.26 to address 14 vulnerabilities: CVE-2026-77692, CVE-2026-76163, CVE-2026-19667, CVE-2026-19666, CVE-2026-80274, CVE-2026-19662, CVE-2026-81563, CVE-2026-81736, CVE-2026-19668, CVE-2026-75029, CVE-2026-19941, CVE-2026-77119, CVE-2026-19033, and CVE-2026-78301. CVE-2026-77692 allows an unauthenticated party to crash named on BIND 9 servers handling DNS-over-HTTPS with a malformed SIG(0) request, while other issues can crash resolvers, exhaust CPU or memory, or enable DNS data integrity attacks under specific conditions. ISC reports no active exploitation; administrators should update BIND 9, noting that the unsupported 9.18 branch has no fixes for 12 of these issues.