Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaws in BIND DNS Servers Threaten Security

Critical Flaws in BIND DNS Servers Threaten Security

Posted on September 18, 2026 By CWS

The Internet Systems Consortium has issued critical updates for BIND 9, addressing 14 vulnerabilities that expose systems to DNS cache poisoning and remote server crashes. These flaws could be exploited to deplete server resources or bypass DNSSEC protections, posing significant risks to enterprise, ISP, and cloud environments.

Urgent Recommendations for Administrators

Administrators managing recursive BIND resolvers are urged to implement the latest updates promptly. The most severe vulnerabilities impact the named daemon, a crucial component for both authoritative and recursive DNS services. Left unpatched, these issues could severely disrupt operations.

Several vulnerabilities can be exploited through malicious DNS responses or specially crafted client queries, making internet-facing resolvers particularly vulnerable. This highlights the need for immediate action to secure these systems.

Threat of DNS Cache Poisoning

Among these vulnerabilities, two are directly linked to DNS cache-poisoning threats. CVE-2025-40778 is notable for its spoofing weaknesses, enabling attackers to inject forged records into a resolver cache when DNSSEC is not enabled or validation is disabled. As a countermeasure, ISC has modified BIND to reject DNAME and unnecessary NS records unless received through spoofing-resistant channels, such as TCP or DNS Cookies.

Another critical issue, CVE-2025-40780, stems from BIND’s previous pseudo-random number generator, which could allow attackers to predict UDP ports and DNS transaction IDs, facilitating cache poisoning. ISC has replaced this with a cryptographically secure generator to fortify against such attacks.

Denial-of-Service Vulnerabilities

Multiple fixes target remote denial-of-service vulnerabilities, including CVE-2026-5947, which causes crashes from SIG(0)-signed responses under load, and CVE-2026-3593, a flaw in DNS-over-HTTPS that could be triggered by a flood of HTTP/2 SETTINGS frames. This could cause the named process to crash while writing a DNS response.

Additional flaws were identified, leading to process termination during TKEY processing, handling of malformed DNSSEC records, and other operations. These vulnerabilities highlight the importance of securing authoritative domains and DNS servers against malformed records that could cause assertion failures and resolver crashes.

Organizations must assess all systems running BIND, particularly those utilizing public recursive resolvers, DNS-over-HTTPS endpoints, or DNSSEC-validating resolvers. Upgrading to a supported BIND release and monitoring for unusual activity is essential to maintaining security.

These updates underscore the critical nature of DNS infrastructure as a target for attacks. Successful cache-poisoning can redirect users to malicious sites, while remote crashes could disrupt vital network services. Proactively addressing these vulnerabilities is crucial to safeguarding network integrity.

Cyber Security News Tags:BIND DNS, cache poisoning, CVE-2025-40778, CVE-2025-40780, CVE-2026-3593, CVE-2026-5947, Cybersecurity, denial of service, DNS vulnerabilities, DNS-over-HTTPS, DNSSEC, Internet Systems Consortium, network security, remote crashes, security update

Post navigation

Previous Post: Orkes Conductor Flaw Exploited in Recent Cyber Attacks
Next Post: AI-Assisted Malware Targets npm Users with PhantomRaven

Related Posts

United Natural Foods Suffers Cyberattack United Natural Foods Suffers Cyberattack Cyber Security News
Feiniu NAS Devices Targeted in Major Botnet Attack Feiniu NAS Devices Targeted in Major Botnet Attack Cyber Security News
Critical Flaw in Perplexity’s Comet Browser Exploited Critical Flaw in Perplexity’s Comet Browser Exploited Cyber Security News
MacOS Users Alert: ClickFix Domains Conceal Atomic Stealer MacOS Users Alert: ClickFix Domains Conceal Atomic Stealer Cyber Security News
Docker Open Sources Production-Ready Hardened Images for Free Docker Open Sources Production-Ready Hardened Images for Free Cyber Security News
Beware of Weaponized AI Tool Installers That Infect Your Devices With Ransomware Beware of Weaponized AI Tool Installers That Infect Your Devices With Ransomware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Recommends Cyber Decoys to Detect Hackers
  • Critical Vulnerabilities Patched by Top Cybersecurity Firms
  • AI-Assisted Malware Targets npm Users with PhantomRaven
  • Critical Flaws in BIND DNS Servers Threaten Security
  • Orkes Conductor Flaw Exploited in Recent Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Recommends Cyber Decoys to Detect Hackers
  • Critical Vulnerabilities Patched by Top Cybersecurity Firms
  • AI-Assisted Malware Targets npm Users with PhantomRaven
  • Critical Flaws in BIND DNS Servers Threaten Security
  • Orkes Conductor Flaw Exploited in Recent Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark