Data Exposure Risk in BIND 9 by Internet Systems Consortium
CVE-2026-19033

6.5MEDIUM

Key Information:

Vendor

Isc

Status
Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-19033?

This vulnerability in BIND 9 allows an unauthorized entity to potentially access zone data during a multi-message TCP IXFR transfer, as named may serve this data prior to receiving the final TSIG signature. In cases where the TSIG is invalid or missing, BIND does not revert to the previous state, creating a significant risk for data exposure and unauthorized server content sharing.

Affected Version(s)

BIND 9 9.11.0 <= 9.18.50

BIND 9 9.20.0 <= 9.20.27

BIND 9 9.21.0 <= 9.21.25

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.