BIND 9 patches 14 flaws including an unauthenticated DNS-over-HTTPS crash from a single request
On September 16, 2026 the ISC shipped BIND 9.20.29 and 9.21.26 to fix 14 vulnerabilities, including CVE-2026-77692, which crashes named with a single malformed DNS-over-HTTPS request. Inventory every resolver, patch, and make resolution redundant before one packet takes your platform down.