Vulnerability in BIND Resolver Affects ISC BIND Products
CVE-2026-13321

8.6HIGH

Key Information:

Vendor

Isc

Status
Vendor
CVE Published:
22 July 2026

Badges

👾 Exploit Exists

What is CVE-2026-13321?

The BIND DNS resolver has a security issue involving the handling of validly-signed NSEC records. In this scenario, the 'Next Domain Name' field can point to an area outside the signer's zone, potentially leading to unexpected behavior and increased risk of exploitation. This affects specific versions of BIND, prompting the need for users to check and update their systems to maintain optimal security and functionality.

Affected Version(s)

BIND 9 9.11.0 <= 9.18.50

BIND 9 9.20.0 <= 9.20.24

BIND 9 9.21.0 <= 9.21.23

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ISC would like to thank Qifan Zhang of Palo Alto Networks for bringing this vulnerability to our attention.
.