Vulnerabilities & Exploits
Unbound Patch Shifts Priority to DNS Resolvers Oracle patched 19 Oracle VM VirtualBox flaws and said one, CVE-2026-87277 , can be abused remotely over RDP without authentication. But NLnet Labs also shipped Unbound 1.26.1 to fix a critical DNSSEC heap overflow, CVE-2026-81642 , that a malicious DNS zone can trigger when a vulnerable resolver queries it.
In plain terms, the resolver can be fed crafted DNSSEC data and then mis-handle it until memory is corrupted, which NLnet Labs says can lead to remote code execution. That makes the exposure network-reachable: the attacker needs the resolver to process their zone, not local access to the host.
For operators, the practical priority now sits with internet-facing Unbound resolvers that validate DNSSEC from untrusted zones. VirtualBox still needs patching, but this change moves the urgent blast radius to the naming infrastructure that sits on the public path.
17 sources · Sep 19
CVE-2026-81642 NVD KEV
EPSS 1.0% (60th percentile).
CVE-2026-82717 NVD KEV
EPSS 0.8% (54th percentile).
Timeline Sources Sep 19 The Hacker News
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
CISA added three actively exploited Linux kernel flaws to its KEV catalog, including bugs that can enable local privilege escalation and DoS.
original Sep 17 The Hacker News
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Unbound 1.26.1 fixes a critical DNSSEC heap overflow that malicious zones can trigger, with possible remote code execution.
original Sep 17 NCSC-NL Advisories
Kwetsbaarheden verholpen in Oracle VM VirtualBox
Oracle heeft 19 kwetsbaarheden verholpen in Oracle VM VirtualBox.
original Part of the PlainSec briefing for 2026-09-14
Every edition of this story: Unbound Patch Shifts Priority to DNS Resolvers
More from today
Vulnerabilities & Exploits
Unbound Patch Shifts Priority to DNS Resolvers Oracle patched 19 Oracle VM VirtualBox flaws and said one, CVE-2026-87277 , can be abused remotely over RDP without authentication. But NLnet Labs also shipped Unbound 1.26.1 to fix a critical DNSSEC heap overflow, CVE-2026-81642 , that a malicious DNS zone can trigger when a vulnerable resolver queries it.
In plain terms, the resolver can be fed crafted DNSSEC data and then mis-handle it until memory is corrupted, which NLnet Labs says can lead to remote code execution. That makes the exposure network-reachable: the attacker needs the resolver to process their zone, not local access to the host.
For operators, the practical priority now sits with internet-facing Unbound resolvers that validate DNSSEC from untrusted zones. VirtualBox still needs patching, but this change moves the urgent blast radius to the naming infrastructure that sits on the public path.
17 sources · Sep 19
CVE-2026-81642 NVD KEV
EPSS 1.0% (60th percentile).
CVE-2026-82717 NVD KEV
EPSS 0.8% (54th percentile).
Timeline Sources Sep 19 The Hacker News
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
CISA added three actively exploited Linux kernel flaws to its KEV catalog, including bugs that can enable local privilege escalation and DoS.
original Sep 17 The Hacker News
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Unbound 1.26.1 fixes a critical DNSSEC heap overflow that malicious zones can trigger, with possible remote code execution.
original Sep 17 NCSC-NL Advisories
Kwetsbaarheden verholpen in Oracle VM VirtualBox
Oracle heeft 19 kwetsbaarheden verholpen in Oracle VM VirtualBox.
original Part of the PlainSec briefing for 2026-09-14
Every edition of this story: Unbound Patch Shifts Priority to DNS Resolvers
More from today