CVE-2026-81642
EPSS 1.0% (60th percentile).
Vulnerabilities · 9 days ago
Oracle patched 19 Oracle VM VirtualBox flaws and said one, CVE-2026-87277, can be abused remotely over RDP without authentication. But NLnet Labs also shipped Unbound 1.26.1 to fix a critical DNSSEC heap overflow, CVE-2026-81642, that a malicious DNS zone can trigger when a vulnerable resolver queries it.
In plain terms, the resolver can be fed crafted DNSSEC data and then mis-handle it until memory is corrupted, which NLnet Labs says can lead to remote code execution. That makes the exposure network-reachable: the attacker needs the resolver to process their zone, not local access to the host.
For operators, the practical priority now sits with internet-facing Unbound resolvers that validate DNSSEC from untrusted zones. VirtualBox still needs patching, but this change moves the urgent blast radius to the naming infrastructure that sits on the public path.
EPSS 1.0% (60th percentile).
EPSS 0.8% (54th percentile).
17 sources covering this story
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
CISA added three actively exploited Linux kernel flaws to its KEV catalog, including bugs that can enable local privilege escalation and DoS.
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Unbound 1.26.1 fixes a critical DNSSEC heap overflow that malicious zones can trigger, with possible remote code execution.
Kwetsbaarheden verholpen in Oracle VM VirtualBox
Oracle heeft 19 kwetsbaarheden verholpen in Oracle VM VirtualBox.
Zero Day Initiative — The Apple Security Update Review for September 2026
Welcome back to our monthly look at Apple security patches. This release shows Apple is not immune to the new normal of AI-assisted vulnerability discovery as they release patches for 273 total CVEs. For the September 2026 release, Apple released 273 unique CVEs across macOS 27 (Golden Gate), macOS
Oracle Critical Security Patch Update, September 2026 Review | Qualys
Oracle released its September edition of Critical Security Patch Update.
Kwetsbaarheden verholpen in Oracle PeopleSoft Enterprise
De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle PeopleSoft-producten, waaronder mogelijkheden voor...
Kwetsbaarheden verholpen in Oracle Java SE
Oracle heeft 3 kwetsbaarheden verholpen in Oracle Java SE, waaronder Oracle GraalVM for JDK en Oracle GraalVM Enterprise Edition.
Kwetsbaarheden verholpen in Oracle Financial Services
De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle...
Kwetsbaarheden verholpen in Oracle Enterprise Manager
De beveiligingsupdates zijn niet van toepassing op client-only installaties waarop Oracle Enterprise Manager niet is...
Kwetsbaarheden verholpen in Oracle E-Business Suite
Oracle heeft 159 kwetsbaarheden verholpen in diverse Oracle E-Business Suite-producten, waaronder Oracle Applications Framework, Oracle Document Management and Collaboration, Oracle Mobile Application Server, Oracle Alert, Oracle Application Object Library, Oracle Applications Manager, Oracle Bills of Material, Oracle Complex Maintenance, Repair and...
Kwetsbaarheden verholpen in Oracle Communications
Oracle heeft 31 kwetsbaarheden verholpen in diverse Oracle Communications-producten, waaronder Oracle Communications Unified Assurance, Oracle Communications Cloud Native Core Security Edge Protection Proxy, Oracle Communications MetaSolv Solution Module - ASR, Oracle Communications Service Catalog and Design en Oracle Communications Operations Monitor.
Kwetsbaarheden verholpen in Oracle Commerce Platform
De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle Commerce-producten, waaronder mogelijkheden voor...
Part of the PlainSec briefing for 2026-09-18