Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ISC Updates BIND 9 to Fix 14 Critical Flaws

ISC Updates BIND 9 to Fix 14 Critical Flaws

Posted on September 17, 2026 By CWS

The Internet Systems Consortium (ISC) has recently issued new security updates for BIND 9, a prominent open-source DNS server software. This update addresses 14 vulnerabilities, with seven marked as high severity, which could potentially lead to denial-of-service (DoS) conditions.

High-Severity Vulnerabilities Identified

Among the 14 flaws, seven are notably severe, posing risks such as unexpected program termination, memory depletion, named termination, and resource exhaustion, all of which can result in DoS scenarios. These vulnerabilities can be remotely exploited.

The identified high-severity bugs are labeled as CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736. They can be triggered through various means such as mismatched NOQNAME proof, QTYPE TKEY queries, malformed authoritative server responses, SVCB/HTTPS AliasMode records, crafted DNS-over-HTTPS (DoH) requests, and excessively large negative responses.

Noteworthy Remote Exploit

Particularly concerning is CVE-2026-77692, which can be exploited without authentication. A single crafted DoH SIG(0) request can cause the ‘named’ process to crash. ISC elaborates that an attacker could send a specially crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, then prematurely close the transport connection to trigger an abort.

Medium-Severity Flaws and Updates

The update also addresses seven medium-severity vulnerabilities. These issues could lead to cache poisoning, excessive memory usage in the negative cache, CPU exhaustion, packet loss, and arbitrary data insertion into a zone, as well as DoS attacks. All vulnerabilities have been fixed with the release of BIND versions 9.21.26 and 9.20.29.

While ISC has reported no known active exploitation of these vulnerabilities, it strongly advises users to update their BIND deployments promptly. Additional details can be found in the BIND security advisories and release notes.

For further context, similar security updates have been recently issued by other major tech companies, including Oracle and Apple, addressing hundreds of vulnerabilities.

Security Week News Tags:BIND 9, cache poisoning, CVE, Cybersecurity, DNS Server, DNS-over-HTTPS, DoS attack, ISC, malware protection, named termination, remote exploit, security update, SIG(0), software patch, Vulnerabilities

Post navigation

Previous Post: OpenAI Discloses Six AI Model Failures and New Framework
Next Post: FamousSparrow’s New Backdoor Targets Exchange Servers

Related Posts

Data Breach Affects 280,000 at Premier Medical Group Data Breach Affects 280,000 at Premier Medical Group Security Week News
Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers Security Week News
Cisco Addresses New SD-WAN Zero-Day Security Flaw Cisco Addresses New SD-WAN Zero-Day Security Flaw Security Week News
Palo Alto Networks Patches Privilege Escalation Vulnerabilities Palo Alto Networks Patches Privilege Escalation Vulnerabilities Security Week News
Hacker Conversations: McKenzie Wark, Author of A Hacker Manifesto Hacker Conversations: McKenzie Wark, Author of A Hacker Manifesto Security Week News
Phishers Abuse SharePoint in New Campaign Targeting Energy Sector Phishers Abuse SharePoint in New Campaign Targeting Energy Sector Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages
  • Phishing Scam Targets T-Mobile Users with Fake Rewards
  • Global Crackdown Halts NightmareStresser DDoS Service

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages
  • Phishing Scam Targets T-Mobile Users with Fake Rewards
  • Global Crackdown Halts NightmareStresser DDoS Service

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark