Vulnerabilities & Exploits · DDoS

ISC BIND Patch Leaves 9.18 Users Behind

ISC has released BIND 9.20.29, 9.21.26, and BIND Supported Preview Edition 9.20.29-S1 to fix 14 denial-of-service flaws, including seven rated high. One of the crashes needs only a crafted DNS-over-HTTPS request and no credentials: ISC says a bad SIG(0) signature and a closed connection can make named abort.

The mechanism is a service crash, not code execution. In the DoH case, the server starts checking the signature and dies if the sender drops the connection before that check finishes; other flaws can drain memory or CPU, or terminate the resolver under crafted DNS traffic.

The catch is the packaging gap: ISC ended support for 9.18 and shipped no 9.18 fix, yet some operating-system packages still carry 9.18 builds. For DNS operators and distro maintainers, the exposure now sits with downstream packaging as much as with ISC itself.

3 sources · Sep 17

CVEs in this update

6 CVEs

Across BIND, BIND 9.

0 critical · 5 high · 1 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-80274 · 7.5 HIGH

Highest EPSS: CVE-2026-80274 · 0.49%

Timeline

Sources

Part of the PlainSec briefing for 2026-09-17

Every edition of this story: ISC BIND Patch Leaves 9.18 Users Behind

More from today