CVE-2026-77692
Unauthenticated remote crash of named via a single DoH SIG(0) request
Description
An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1.
In plain language
AI Act nowbind 9 servers running versions 9.20.0-9.20.27, 9.21.0-9.21.25, or 9.20.9-S1-9.20.27-S1 can be knocked offline remotely, so affected small businesses should act now.
Unauthenticated remote denial of service in bind 9’s DNS-over-HTTPS handling: a malformed SIG(0) record followed by an abruptly closed connection triggers a null-pointer dereference and crashes named.
What to do now
- Check whether you run bind 9 and whether its DNS-over-HTTPS endpoint is enabled and reachable from the internet.
- Check the installed version with
named -vor your server’s package manager. - Upgrade to 9.20.29, 9.21.26, or 9.20.29-S1, choosing the patched release for your current branch.
- Restart the DNS service and confirm it is answering requests normally after the upgrade.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- 21st September – Threat Intelligence Reporten-us·Check Point Research· Exploited Japan Digital Agency Government Solution Service WaterPlum
- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacksen·The Hacker News· Exploited Cisco Identity Services Engine zero-day
- ISC Patches 14 Vulnerabilities in BIND 9 Security Updateen-us·SecurityWeek· Patch BIND 9 ddos-botnet
- BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPSen·The Hacker News· Patch BIND 9 network-edge
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-77692 and every CVE in our database. Create a free account — no credit card required.
Create Free Account