Junglewise Threat Intelligence

CVE-2026-77505: DNS Server use-after-free remote code execution

CVE-2026-77505 · Severity: high · CVSS 8.1 · Published 2026-09-08

Executive brief

A DNS Server component is vulnerable to a use-after-free memory defect that allows an unauthenticated attacker to execute arbitrary code remotely over a network. Exploitation could result in complete system compromise, allowing an attacker to take control of the DNS server and potentially intercept or redirect network traffic for downstream systems.

Technical details

The vulnerability is a use-after-free (CWE-416) condition in the DNS Server service that allows an unauthenticated network attacker to achieve remote code execution. The exact vulnerable component and root cause are not detailed in the available advisory content, but the defect allows memory that has been freed to be accessed and potentially dereferenced. An attacker on the network can trigger this condition without authentication, leading to out-of-bounds memory access and arbitrary code execution with the privileges of the DNS Server service. A patch is expected from the vendor.

Affected products

  • DNS Server

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References