Vulnerabilities & Exploits

Unbound Patch Shifts Priority to DNS Resolvers

Oracle patched 19 Oracle VM VirtualBox flaws and said one, CVE-2026-87277, can be abused remotely over RDP without authentication. But NLnet Labs also shipped Unbound 1.26.1 to fix a critical DNSSEC heap overflow, CVE-2026-81642, that a malicious DNS zone can trigger when a vulnerable resolver queries it.

In plain terms, the resolver can be fed crafted DNSSEC data and then mis-handle it until memory is corrupted, which NLnet Labs says can lead to remote code execution. That makes the exposure network-reachable: the attacker needs the resolver to process their zone, not local access to the host.

For operators, the practical priority now sits with internet-facing Unbound resolvers that validate DNSSEC from untrusted zones. VirtualBox still needs patching, but this change moves the urgent blast radius to the naming infrastructure that sits on the public path.

17 sources · Sep 19

CVE-2026-81642

NVD KEV

EPSS 1.0% (60th percentile).

CVE-2026-82717

NVD KEV

EPSS 0.8% (54th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-09-18

Every edition of this story: Unbound Patch Shifts Priority to DNS Resolvers

More from today