-Infinity
0

ISC BIND 9DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field

Risk 51
Severity
8.6
First published (updated )

ISC BIND 9Unexpected exit in certain situations with NSEC and NSEC3 both present

Risk 46
Severity
7.5
First published (updated )

ISC BIND 9Record ordering based unexpected exit with CNAME or DNAME

Risk 46
Severity
7.5
First published (updated )

ISC BIND 9Cache poisoning possible with label count discrepancy, RRSIG, and wildcards

Risk 46
Severity
7.5
First published (updated )

ISC BIND 9Potential memory usage beyond configured limits

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ISC BIND 9Unnecessary validation of DNSSEC signed records

Risk 46
Severity
7.5
First published (updated )

ISC BIND 9Potential wildcard CNAME RPZ policy bypass

Risk 46
Severity
7.5
First published (updated )

ISC BIND 9Key Record using PRIVATEDNS algorithm may lead to unexpected exit

Risk 39
Severity
6.5
First published (updated )

ISC BIND 9Incorrect acceptance of NSEC3 records

Risk 42
Severity
6.8
First published (updated )

oss-secISC has disclosed nine vulnerabilities in BIND 9 (CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321)

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ISC BIND RecursorInsufficient input validation in ZoneToCache

Risk 37
Severity
5.9
First published (updated )

oss-secCoordinated Disclosuin the LLM Age

oss-secCoordinated Disclosuin the LLM Age

ISC BINDUnbounded resend loop in BIND 9 resolver

Risk 29
Severity
5.3
First published (updated )

ISC BINDAmplification vulnerabilities via self-pointed glue records

Risk 29
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ISC BINDSIG(0) validation during query flood may lead to undefined behavior

Risk 46
Severity
7.5
First published (updated )

ISC BINDUse After Free, Race Condition

Risk 33
Severity
7
First published (updated )

ISC BINDInvalid handling of CLASS != IN

Risk 46
Severity
7.5
First published (updated )

ISC BIND (named)Multiple flaws have been identified in named related to the handling of DNS messages whose CLASS is …

Risk 33
Severity
7
First published (updated )

ISC BINDHeap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation

Risk 92
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ISC BINDBIND 9 server memory exhaustion during GSS-API TKEY negotiation

Risk 46
Severity
7.5
First published (updated )

ISC BINDBIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable …

Risk 33
Severity
7
First published (updated )

FreeBSD FreeBSDRemote code execution via malicious DHCP options

Risk 78
Severity
8.1
First published (updated )

ISC dhcpcdDhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling

Risk 38
Severity
6.5
First published (updated )

PowerDNS recursorNull pointer dereference in RPZ transfer

Risk 31
Severity
4.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ISC DHCPv6 (helper process in helper.c)In helper.c:265, the DHCPv6 CLID is hex-encoded via sprintf("%.2x") into daemon->packet (5,131 bytes…

Risk 33
Severity
7
First published (updated )

ISC BIND 9If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the re…

Risk 33
Severity
7
First published (updated )

ISC BIND 9A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying …

Risk 33
Severity
7
First published (updated )

ISC BINDA stack use-after-return flaw in SIG(0) handling code may enable ACL bypass

Risk 26
Severity
5.4
EPSS
0.02%
First published (updated )

ISC BINDAuthenticated query containing a TKEY record may cause named to terminate unexpectedly

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203