NSEC Record Vulnerability in BIND Resolver by ISC
CVE-2026-19941

5.9MEDIUM

Key Information:

Vendor

Isc

Status
Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-19941?

A vulnerability in ISC's BIND resolver allows the acceptance of an inappropriate NSEC record, potentially enabling an attacker to obscure the presence of a wildcard record within the zone. This flaw affects multiple versions of BIND and could lead to serious implications for DNS security, as malicious entities could manipulate DNS responses and compromise domain name integrity.

Affected Version(s)

BIND 9 9.11.0 <= 9.18.50

BIND 9 9.20.0 <= 9.20.27

BIND 9 9.21.0 <= 9.21.25

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.