DNSSEC Vulnerability in BIND Resolver from ISC
CVE-2026-80274

7.5HIGH

Key Information:

Vendor

Isc

Status
Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-80274?

A vulnerability exists within the BIND resolver that can lead to an unexpected program exit when a query for a DNSSEC-signed authoritative zone is processed. If the authoritative server responds with a valid wildcard answer along with a signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it triggers this instability. This issue affects multiple versions of BIND 9, causing critical concern for users relying on the resolver for DNS services. Users are strongly advised to update to the latest versions to mitigate potential disruptions.

Affected Version(s)

BIND 9 9.11.0 <= 9.18.50

BIND 9 9.20.0 <= 9.20.27

BIND 9 9.21.0 <= 9.21.25

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ISC would like to thank hythyt for bringing this vulnerability to our attention.
.