CVE-2026-76163
named aborts on a TKEY query when the user configuration has no global options statement
Description
If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacksen·The Hacker News· Exploited Cisco Identity Services Engine zero-day
- ISC Patches 14 Vulnerabilities in BIND 9 Security Updateen-us·SecurityWeek· Patch BIND 9 ddos-botnet
- BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPSen·The Hacker News· Patch BIND 9 network-edge
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-76163 and every CVE in our database. Create a free account — no credit card required.
Create Free Account