FR
live

BIND 9 patches 14 flaws that enable DNS cache poisoning and DNSSEC bypass

On 16 September 2026, ISC shipped BIND 9.20.29 and 9.21.26, fixing 14 vulnerabilities including DNS cache-poisoning flaws and DNSSEC-validation bypasses. Upgrade exposed recursive resolvers and lock down recursion before a forged response redirects your users.

A wall of dark brass card-catalog drawers in a dim archive, one drawer pulled open with a single amber index card filed in the wrong alphabetical slot.

16 September 2026. The Internet Systems Consortium (ISC) releases BIND 9.20.29 and 9.21.26. 16 September 2026. The announcement discloses that the two releases fix 14 vulnerabilities in the named daemon. 21 September 2026. India’s CERT-In wraps the set into a single note (CIVN-2026-0467) that names cache poisoning and unauthorized zone injection among the possible outcomes. Why it matters: BIND 9 is still the reference DNS server of the internet — the resolver behind ISPs, clouds and enterprises — and a cache-poisoning flaw is the ability to silently point an entire domain at an attacker-controlled machine.

Cache poisoning is the integrity attack that makes no noise

Two of the fourteen flaws bear directly on an attacker’s ability to poison the cache of a recursive resolver. They are the most serious of the batch, and by a wide margin: unlike a denial of service, which breaks service and shows up instantly, cache poisoning corrupts the answer itself without interrupting anything.

CVE-2025-40778 covers several spoofing weaknesses that let a forged record land in a resolver cache when DNSSEC is not enabled, or when validation is disabled. In practice, an attacker who controls an authoritative name server for a subdomain can make the resolver accept unnecessary DNAME or NS records in the authority section of a response — and from there expand their reach toward the parent domain. ISC’s countermeasure is blunt: BIND no longer accepts those records in the authority section unless the response arrives over a spoofing-resistant channel — TCP, DNS Cookies, TSIG or SIG(0).

CVE-2025-40780 targets the pseudo-random number generator (PRNG) that BIND used to pick source UDP ports and transaction IDs. A predictable generator makes both values guessable, which mechanically raises the odds that a forged response is accepted. ISC swapped it for a cryptographically secure generator, making prediction-based poisoning materially harder.

Both fixes share the same through-line: the robustness of the transport layer is what conditions trust in the answer. A resolver that does not authenticate its responses with DNSSEC has nothing left to rely on but the difficulty of guessing packet parameters — and that is exactly what these two flaws weakened.

DNSSEC bypass strikes at the trust root

The second family of flaws weakens DNSSEC, the cryptographic signature mechanism that is supposed to guarantee the integrity of DNS responses. CVE-2026-3104 hits DNSSEC validation itself, while CVE-2025-8677 and CVE-2026-1519 affect the handling of DNSKEY and NSEC3 records respectively.

The stakes go beyond a routine software bug. DNSSEC is the piece that lets you say «this response really came from the legitimate owner of the domain». When its validation can be bypassed, a resolver lands in the exact situation DNSSEC was meant to prevent: it accepts responses it can no longer tell apart from real ones. For an operator who put in the work to sign their zones, a validation flaw on the resolver side cancels part of that effort — without even touching the zone’s own keys.

The operational consequence is direct: trust is not granted once, it is maintained through updates. An unpatched resolver can act as the weak link for an end user whose own domain is perfectly signed.

Remote denial of service, from crashes to exhaustion

The rest of the bulletin fixes remote denial-of-service conditions, several of which can crash the named process with a single forged query or response.

CVE-2026-5947 crashes named on SIG(0)-signed responses received under load. CVE-2026-3593 is a use-after-free in DNS-over-HTTPS (DoH): a flood of HTTP/2 SETTINGS frames sent while BIND is writing a response can trigger a crash. Other flaws can terminate named during TKEY processing, malformed NSEC/NSEC3 responses, DNS64 operations, zone transfers, or CNAME/DNAME chains.

ISC also added resource-exhaustion guardrails: limits on DNSSEC validation work, on the size of name-server lists, on crafted negative responses and on cache growth. These attacks do not crash the server, but consume CPU and memory until legitimate lookups are delayed — an insidious effect that shows up as degradation rather than a hard outage.

What it changes for a network operator

Read as a whole, the set is an inventory of a modern resolver’s surfaces: the cache, validation, DoH, SIG(0), TSIG, zones, DNS64. One bulletin, but every entry point of an exposed named.

For an operator, the lesson comes down to three points. First, open recursion is the universal aggravating factor: a resolver that accepts recursive queries from anyone exposes its cache to poisoning. Second, UDP remains the weak link — ISC is explicitly steering operators toward spoofing-resistant channels (TCP, DNS Cookies, TSIG). Third, integrity is something you monitor: an unexpected named restart, abnormal CPU use or malformed queries in the logs are the early signs of exploitation in progress.

The upgrade narrows to two release targets. The 9.20 and 9.21 series receive 9.20.29 and 9.21.26 respectively; older series are out of support and must migrate. The fix applies without configuration changes for the majority of deployments, which removes any excuse to defer.

Verdict

If you run an internet-exposed recursive BIND resolver, move to 9.20.29 or 9.21.26 within the week — cache poisoning is an integrity attack that leaves no visible trace, and the fixes harden precisely the transport layer that made it possible. If you sign your zones with DNSSEC, check the resolver version of your clients and forwarders in the same pass: a signed zone protects no one if the resolver on the other end bypasses validation. If you only expose authoritative servers, your risk is lower, but the SIG(0) and zone-transfer flaws still apply — schedule the update in your normal cycle. The broader lesson is simple: trust in the DNS is rebuilt at every release, and an unpatched resolver is a resolver that lies without knowing it.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

Two unpatched Citrix NetScaler zero-days are exploited with no fix published

watchTowr has documented two remote-code-execution zero-days in Citrix NetScaler ADC and Gateway, already exploited before any fix existed. With nothing published by Citrix, the only defense is isolation: preserve evidence, cut the appliance off the network and keep management off the internet.

The MikroTrick chain opens the RouterOS admin console with no password or SSH key

CERT Polska has documented the MikroTrick chain: two RouterOS SSH flaws, CVE-2026-67279 and CVE-2026-86060, combine to hand attackers full administrative control of an exposed router with no password and no SSH key. CISA added CVE-2026-67279 to its KEV catalog on September 25, 2026: patch to 6.49.21, 7.23.4 or 7.24.2 and hunt for signs of compromise.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss