Skip to main content
The Wire
CyberNews by Zentrya One
high CVE-2026-77692 and CVE-2026-76163 Vulnerabilities

BIND 9 Update Fixes 14 Security Flaws, Including Unauthenticated DoH Crash

ISC has patched 14 BIND 9 vulnerabilities, including CVE-2026-77692, which allows an unauthenticated DNS-over-HTTPS request to remotely crash vulnerable DNS servers.

The Internet Systems Consortium (ISC) has released security updates for BIND 9, addressing 14 vulnerabilities that could allow remote attackers to crash DNS servers, exhaust CPU or memory resources, or manipulate DNS data under certain conditions.

The updates are available in BIND 9.20.29 and 9.21.26, while Supported Preview Edition customers can update to 9.20.29-S1. ISC says it is currently not aware of active exploitation of any of the vulnerabilities.

Critical Issues to Know

Seven of the 14 vulnerabilities are rated High severity with CVSS 7.5 scores, while the remaining seven are rated Medium.

One of the most notable flaws is CVE-2026-77692, which affects BIND servers providing DNS-over-HTTPS (DoH).

An unauthenticated remote attacker can send a specially crafted request containing an invalid SIG(0) signature and close the connection before BIND completes signature verification.

This can cause the named process to crash, resulting in a denial-of-service condition.

Major Vulnerabilities

CVE Severity Impact
CVE-2026-77692 High – 7.5 Unauthenticated DoH request can crash named
CVE-2026-76163 High – 7.5 TKEY query can crash certain configurations
CVE-2026-19667 High – 7.5 Crafted DNS response can crash resolver
CVE-2026-19666 High – 7.5 DNS64-related use-after-free can crash resolver
CVE-2026-80274 High – 7.5 Crafted DNSSEC response can cause resolver failure
CVE-2026-81563 High – 7.5 SVCB/HTTPS records can cause excessive memory usage
CVE-2026-81736 High – 7.5 SVCB/HTTPS alias trees can cause CPU exhaustion

Several additional Medium-severity vulnerabilities affect DNSSEC validation, zone transfers, caching, and memory or CPU consumption.

DNS Cache Poisoning Risks

Not all of the vulnerabilities are denial-of-service issues.

CVE-2026-19941 can cause a validating resolver to accept an incorrect DNSSEC proof, potentially allowing a forged NXDOMAIN response to be accepted.

Another flaw, CVE-2026-77119, can under specific conditions cause a secure delegation to be treated as unsigned, potentially allowing forged DNS responses to pass validation.

ISC describes the possible outcome of these vulnerabilities as cache poisoning.

Zone Transfer Vulnerability

CVE-2026-19033 affects secondary DNS servers using TSIG-restricted zone transfers.

BIND could begin serving new zone data before the final TSIG signature was verified. If the signature never arrived, the server did not properly restore the previous zone state.

Under the required conditions, an attacker could therefore cause unauthorized zone information to be served without possessing the valid TSIG key.

Affected and Fixed Versions

Administrators should upgrade to:

  • BIND 9.20.29 – fixes all 14 vulnerabilities.
  • BIND 9.21.26 – fixes 13 vulnerabilities; CVE-2026-19662 does not affect this branch.
  • BIND 9.20.29-S1 – fixed Supported Preview Edition release.

Many of the vulnerabilities also affect the older BIND 9.18 branch, which reached end-of-life in June 2026. ISC advises organizations using unsupported releases to migrate to a currently supported BIND version.

No Workarounds Available

ISC has not provided workarounds for the 14 vulnerabilities, making upgrading the primary remediation.

Organizations should:

  • Upgrade BIND immediately to a fixed release.
  • Prioritize internet-facing recursive resolvers and DoH servers.
  • Migrate unsupported BIND 9.18 deployments to BIND 9.20.
  • Monitor named processes for unexpected crashes or restarts.
  • Investigate abnormal CPU or memory consumption.
  • Monitor DNSSEC validation and unusual SVCB/HTTPS activity.

Security Takeaway

The most immediately exploitable issue, CVE-2026-77692, demonstrates that a single unauthenticated DNS-over-HTTPS request can crash a vulnerable BIND server under the required conditions.

However, the broader update is important because the 14 vulnerabilities cover multiple security areas, including:

DoS → Resource Exhaustion → DNSSEC Validation → Cache Poisoning → Zone Integrity

ISC currently reports no known active exploitation, but with technical trigger conditions and reproduction tests now publicly available, administrators should avoid delaying deployment of the patched releases.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.