Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Unauthenticated DNS-over-HTTPS Vulnerabilities Paved the Way for a New Era of Security Concerns




A recent update to the BIND 9 DNS server software has patched 14 security vulnerabilities, including an unauthenticated crash over DNS-over-HTTPS, to ensure the security of DNS-over-HTTPS. The update fixes vulnerabilities identified as follows: CVE-2026-77692, CVE-2026-76163, CVE-2026-19667, CVE-2026-19666, CVE-2026-80274, CVE-2026-19662, CVE-2026-81563, CVE-2026-81736, CVE-2026-19668, CVE-2026-75029, CVE-2026-19941, CVE-2026-77119, CVE-2026-19033, and CVE-2026-78301. The fixes arrive in 9.20.29 rather than 9.20.28 because ISC withdrew 9.20.28 before release after pre-release testing found a regression. Four of the fourteen vulnerabilities were found in ISC's own testing, while the rest were reported by external researchers. The update is available for download and is expected to address the fourteen identified vulnerabilities, including the unauthenticated crash over DNS-over-HTTPS.

  • The recent BIND 9 update fixes 14 security flaws, including an unauthenticated crash over DNS-over-HTTPS.
  • The vulnerabilities were identified and categorized using the Common Vulnerability Scoring System (CVSS).
  • The attackers, including Vitaly Simonovich and Samy Medjahed, have been credited with identifying the vulnerabilities.
  • The fixes are available for download in BIND 9.20.29 and 9.21.26.
  • The update addresses the fourteen identified vulnerabilities, including the unauthenticated crash over DNS-over-HTTPS.



  • The recent BIND 9 update, which fixes 14 security flaws, including an unauthenticated crash over DNS-over-HTTPS, has brought to light the growing concern of DNS security vulnerabilities. The Internet Systems Consortium (ISC) released BIND 9.20.29 and 9.21.26 to address these vulnerabilities, which were disclosed in BIND 9, the open-source DNS server software.

    The vulnerabilities, which affect BIND 9 servers that answer DNS-over-HTTPS requests, were identified as follows: CVE-2026-77692, CVE-2026-76163, CVE-2026-19667, CVE-2026-19666, CVE-2026-80274, CVE-2026-19662, CVE-2026-81563, CVE-2026-81736, CVE-2026-19668, CVE-2026-75029, CVE-2026-19941, CVE-2026-77119, CVE-2026-19033, and CVE-2026-78301.

    According to the Internet Systems Consortium (ISC), the fixes arrive in 9.20.29 rather than 9.20.28 because ISC withdrew 9.20.28 before release after pre-release testing found a regression. Four of the fourteen vulnerabilities were found in ISC's own testing, while the rest were reported by external researchers.

    The vulnerabilities, which have been rated by the Common Vulnerability Scoring System (CVSS) as follows: CVE-2026-77692 (7.5 High), CVE-2026-76163 (7.5 High), CVE-2026-19667 (7.5 High), CVE-2026-19666 (7.5 High), CVE-2026-80274 (7.5 High), CVE-2026-19662 (5.9 Medium), CVE-2026-81563 (7.5 High), CVE-2026-81736 (7.5 High), CVE-2026-19668 (5.3 Medium), CVE-2026-75029 (5.3 Medium), CVE-2026-19941 (5.9 Medium), CVE-2026-77119 (5.9 Medium), CVE-2026-19033 (6.5 Medium), and CVE-2026-78301 (5.8 Medium), are categorized as follows: Crash of named (7.5 High), Crash of named (7.5 High), Crash of resolver (7.5 High), Crash of resolver (7.5 High), Crash of resolver (7.5 High), Cache grows past its limit until resolution fails (7.5 High), CPU exhaustion on resolver (7.5 High), CPU exhaustion on validating resolver (5.3 Medium), Memory use beyond configured limits (5.3 Medium), Forged NXDOMAIN accepted (5.9 Medium), Secure delegation downgraded (5.9 Medium), Unauthorized zone data served by a secondary (6.5 Medium), and Out-of-zone data served as authoritative (5.8 Medium).

    The attackers, who have been identified as Vitaly Simonovich (CVE-2026-77692), Rintaro Kawasugi (CVE-2026-19666 and CVE-2026-19667), Samy Medjahed (Ap4sh) (CVE-2026-19662 and CVE-2026-81563), Henrique Pereira (CVE-2026-78301 and CVE-2026-81736), Owais Lone (thesecguy) (CVE-2026-76163), and hythyt (CVE-2026-80274), have been credited with identifying the vulnerabilities.

    The Internet Systems Consortium (ISC) has released the fixes in BIND 9.20.29 and 9.21.26, which are available for download. The fixes are expected to address the fourteen identified vulnerabilities, including the unauthenticated crash over DNS-over-HTTPS.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Unauthenticated-DNS-over-HTTPS-Vulnerabilities-Paved-the-Way-for-a-New-Era-of-Security-Concerns-ehn.shtml

  • https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-77692

  • https://www.cvedetails.com/cve/CVE-2026-77692/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-76163

  • https://www.cvedetails.com/cve/CVE-2026-76163/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-19667

  • https://www.cvedetails.com/cve/CVE-2026-19667/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-19666

  • https://www.cvedetails.com/cve/CVE-2026-19666/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-80274

  • https://www.cvedetails.com/cve/CVE-2026-80274/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-19662

  • https://www.cvedetails.com/cve/CVE-2026-19662/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-81563

  • https://www.cvedetails.com/cve/CVE-2026-81563/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-81736

  • https://www.cvedetails.com/cve/CVE-2026-81736/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-19668

  • https://www.cvedetails.com/cve/CVE-2026-19668/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-75029

  • https://www.cvedetails.com/cve/CVE-2026-75029/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-19941

  • https://www.cvedetails.com/cve/CVE-2026-19941/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-77119

  • https://www.cvedetails.com/cve/CVE-2026-77119/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-19033

  • https://www.cvedetails.com/cve/CVE-2026-19033/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-78301

  • https://www.cvedetails.com/cve/CVE-2026-78301/


  • Published: Thu Sep 17 11:33:05 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us