The Internet Systems Consortium (ISC) has rolled out updates for its BIND 9 DNS server software to address fourteen security vulnerabilities. These updates, versions 9.20.29 and 9.21.26, were released following the disclosure of these flaws on September 16. One of the most critical issues affects servers that support DNS-over-HTTPS (DoH), allowing an unauthenticated sender to crash the server with a single request. Although ISC has not observed any active exploitation of these vulnerabilities, the potential impact is significant, particularly for servers still running the older 9.18 branch as no further updates will be provided.

Two of the vulnerabilities, classified as CVE-2026-77692 and CVE-2026-76163, allow an attack to be executed through a simple request, affecting only the 9.20 and 9.21 branches. Other vulnerabilities require crafted responses to trigger crashes or resource exhaustion, with some rated as high-severity by ISC. These include risks of cache poisoning, where DNS data integrity is compromised. The vulnerabilities rated High on the CVSS scale involve scenarios where a recursive resolver receives specially crafted data from a server controlled by an attacker.

ISC has emphasized the importance of updating to the latest versions, as the older 9.18 branch is no longer supported and remains vulnerable to new CVEs. The organization also noted that none of these vulnerabilities are listed in CISA's Known Exploited Vulnerabilities catalog. However, tests reproducing these flaws are publicly available. The updates, according to ISC, are part of a broader effort to address security issues in every monthly maintenance release due to increased vulnerability reports.

Security teams should prioritize applying these updates to mitigate risks associated with these vulnerabilities. ISC has confirmed that four of these issues were identified internally, while others were reported by independent researchers. This proactive approach is crucial in maintaining the security integrity of DNS infrastructure worldwide.