
Internet Systems Consortium (ISC) has released fresh security updates for BIND, the widely used open source DNS server software, resolving 14 vulnerabilities that could lead to denial-of-service (DoS) attacks.
Seven are high-severity flaws that could be exploited to cause an unexpected program exit, memory exhaustion, named termination, and resource exhaustion, causing DoS conditions.
The remotely exploitable bugs are tracked as CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736.
They can be triggered using mismatched NOQNAME proof, QTYPE TKEY queries, malformed answers from the authoritative server, SVCB/HTTPS AliasMode records, crafted DNS-over-HTTPS (DoH) requests, and negative answers of 65,536 bytes.
CVE-2026-77692 stands out because it can be exploited remotely without authentication to crash named with a single DoH SIG(0) request.
“An attacker can cause named to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely,” ISC explains.
The BIND updates also resolve seven medium-severity vulnerabilities that could lead to cache poisoning, increased memory usage of the negative cache, CPU exhaustion and packet loss, arbitrary attacker-supplied data being added to a zone, and DoS attacks.
All security defects were addressed with the release of BIND versions 9.21.26 and 9.20.29.
ISC says it is not aware of any of the resolved bugs being exploited in the wild, but recommends updating BIND deployments as soon as possible.
Additional information is available on the BIND security advisories page and on BIND 9’s release notes page.
Related: Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
Related: Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
Related: Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

