BIND Vulnerability Allows Forged NXDOMAIN Responses
CVE-2026-10723

6.8MEDIUM

Key Information:

Vendor

Isc

Status
Vendor
CVE Published:
22 July 2026

Badges

👾 Exploit Exists

What is CVE-2026-10723?

BIND contains a vulnerability where it may incorrectly validate child-zone NSEC3 records. This flaw could enable an attacker to craft fraudulent authenticated NXDOMAIN responses, leading to potential misuse in DNS resolution and adversely affecting network security. Users of affected BIND versions should consider implementing patches to mitigate this risk.

Affected Version(s)

BIND 9 9.18.0 <= 9.18.50

BIND 9 9.20.0 <= 9.20.24

BIND 9 9.21.0 <= 9.21.23

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ISC would like to thank Qifan Zhang of Palo Alto Networks for bringing this vulnerability to our attention.
.