Technology · Isc
Isc BIND 9 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in Isc BIND 9: 0 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-13321, was published on 22 July 2026.
- Last 7 days
- 0
- Last 90 days
- 9
- Critical, all time
- 0
- Exploited in the wild
- 0
About Isc BIND 9
BIND 9 is a widely used open-source Domain Name System (DNS) software suite.
Latest Isc BIND 9 vulnerabilities
- CVE-2026-13321: ISC BIND DNSSEC validation bypass in NSEC recordshighCVSS 8.6
- CVE-2026-13204: ISC BIND 9 denial of service via NSEC and NSEC3 assertion failurehighCVSS 7.5
- CVE-2026-12617: ISC BIND 9 denial of service via CNAME or DNAME record orderinghighCVSS 7.5
- CVE-2026-11721: ISC BIND 9 cache poisoning via RRSIG label count discrepancyhighCVSS 7.5
- CVE-2026-11622: ISC BIND 9 resource exhaustion in DNSSEC validating resolverhighCVSS 7.5
- CVE-2026-11605: ISC BIND 9 resource exhaustion in DNSSEC validationhighCVSS 7.5
- CVE-2026-11331: ISC BIND 9 RPZ policy bypass and denial of servicehighCVSS 7.5
- CVE-2026-10822: ISC BIND assertion failure via malformed PRIVATEDNS recordmediumCVSS 6.5
- CVE-2026-10723: ISC BIND incorrect NSEC3 record validationmediumCVSS 6.8
- CVE-2026-5950: ISC BIND 9 unbounded resend loop in resolver state machinemediumCVSS 5.3
- CVE-2026-5947: ISC BIND 9 use-after-free in SIG(0) validation during query floodhighCVSS 7.5
- CVE-2026-5946: ISC BIND 9 denial of service in named via non-IN DNS classeshighCVSS 7.5
- CVE-2026-3593: ISC BIND 9 use-after-free in DNS-over-HTTPS implementationhighCVSS 7.4
- CVE-2026-3592: ISC BIND resource exhaustion in DNS resolvermediumCVSS 5.3
- CVE-2026-3039: ISC BIND 9 memory exhaustion in GSS-API TKEY negotiationhighCVSS 7.5
- CVE-2026-3591: ISC BIND 9 stack use-after-return in SIG(0) handlingmediumCVSS 5.4EPSS 0.0%
- CVE-2026-3119: ISC BIND 9 denial of service via TKEY record in authenticated querymediumCVSS 6.5EPSS 0.0%
- CVE-2026-3104: ISC BIND 9 memory leak in DNSSEC proof-of-non-existence codehighCVSS 7.5EPSS 0.1%
- CVE-2026-1519: ISC BIND 9 denial of service via excessive NSEC3 iterationshighCVSS 7.5EPSS 0.0%
- CVE-2025-13878: ISC BIND 9 denial of service via malformed BRID or HHIT recordshighCVSS 7.5EPSS 7.6%
Most severe Isc BIND 9 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-13321: ISC BIND DNSSEC validation bypass in NSEC recordshighCVSS 8.6
- CVE-2025-13878: ISC BIND 9 denial of service via malformed BRID or HHIT recordshighCVSS 7.5EPSS 7.6%
- CVE-2026-3104: ISC BIND 9 memory leak in DNSSEC proof-of-non-existence codehighCVSS 7.5EPSS 0.1%
- CVE-2026-1519: ISC BIND 9 denial of service via excessive NSEC3 iterationshighCVSS 7.5EPSS 0.0%
- CVE-2026-13204: ISC BIND 9 denial of service via NSEC and NSEC3 assertion failurehighCVSS 7.5
- CVE-2026-12617: ISC BIND 9 denial of service via CNAME or DNAME record orderinghighCVSS 7.5
- CVE-2026-11721: ISC BIND 9 cache poisoning via RRSIG label count discrepancyhighCVSS 7.5
- CVE-2026-11622: ISC BIND 9 resource exhaustion in DNSSEC validating resolverhighCVSS 7.5
- CVE-2026-11605: ISC BIND 9 resource exhaustion in DNSSEC validationhighCVSS 7.5
- CVE-2026-11331: ISC BIND 9 RPZ policy bypass and denial of servicehighCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 9 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/bind-9.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Isc BIND 9 vulnerabilities", https://junglewise.ai/threats/technologies/bind-9, 26 September 2026.