{"schema_version":1,"title":"Isc BIND 9 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 20 vulnerabilities in Isc BIND 9: 0 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-13321, was published on 22 July 2026.","url":"https://junglewise.ai/threats/technologies/bind-9","json_url":"https://junglewise.ai/threats/technologies/bind-9.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/bind-9","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":14,"all_time":20,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":9,"last_365_days":20},"latest":[{"cve":"CVE-2026-13321","cvss":8.6,"slug":"cve-2026-13321-isc-bind-dnssec-validation-bypass-in-nsec-records","title":"ISC BIND DNSSEC validation bypass in NSEC records","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:52.2+00:00","url":"https://junglewise.ai/threats/cve-2026-13321-isc-bind-dnssec-validation-bypass-in-nsec-records"},{"cve":"CVE-2026-13204","cvss":7.5,"slug":"cve-2026-13204-isc-bind-9-denial-of-service-via-nsec-and-nsec3-assertion-failure","title":"ISC BIND 9 denial of service via NSEC and NSEC3 assertion failure","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:52.08+00:00","url":"https://junglewise.ai/threats/cve-2026-13204-isc-bind-9-denial-of-service-via-nsec-and-nsec3-assertion-failure"},{"cve":"CVE-2026-12617","cvss":7.5,"slug":"cve-2026-12617-isc-bind-9-denial-of-service-via-cname-or-dname-record-ordering","title":"ISC BIND 9 denial of service via CNAME or DNAME record ordering","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:51.963+00:00","url":"https://junglewise.ai/threats/cve-2026-12617-isc-bind-9-denial-of-service-via-cname-or-dname-record-ordering"},{"cve":"CVE-2026-11721","cvss":7.5,"slug":"cve-2026-11721-isc-bind-9-cache-poisoning-via-rrsig-label-count-discrepancy","title":"ISC BIND 9 cache poisoning via RRSIG label count discrepancy","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:51.837+00:00","url":"https://junglewise.ai/threats/cve-2026-11721-isc-bind-9-cache-poisoning-via-rrsig-label-count-discrepancy"},{"cve":"CVE-2026-11622","cvss":7.5,"slug":"cve-2026-11622-isc-bind-9-resource-exhaustion-in-dnssec-validating-resolver","title":"ISC BIND 9 resource exhaustion in DNSSEC validating resolver","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:51.703+00:00","url":"https://junglewise.ai/threats/cve-2026-11622-isc-bind-9-resource-exhaustion-in-dnssec-validating-resolver"},{"cve":"CVE-2026-11605","cvss":7.5,"slug":"cve-2026-11605-isc-bind-9-resource-exhaustion-in-dnssec-validation","title":"ISC BIND 9 resource exhaustion in DNSSEC validation","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:51.573+00:00","url":"https://junglewise.ai/threats/cve-2026-11605-isc-bind-9-resource-exhaustion-in-dnssec-validation"},{"cve":"CVE-2026-11331","cvss":7.5,"slug":"cve-2026-11331-isc-bind-9-rpz-policy-bypass-and-denial-of-service","title":"ISC BIND 9 RPZ policy bypass and denial of service","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:51.457+00:00","url":"https://junglewise.ai/threats/cve-2026-11331-isc-bind-9-rpz-policy-bypass-and-denial-of-service"},{"cve":"CVE-2026-10822","cvss":6.5,"slug":"cve-2026-10822-isc-bind-assertion-failure-via-malformed-privatedns-record","title":"ISC BIND assertion failure via malformed PRIVATEDNS record","severity":"medium","exploited":false,"published_at":"2026-07-22T15:16:51.33+00:00","url":"https://junglewise.ai/threats/cve-2026-10822-isc-bind-assertion-failure-via-malformed-privatedns-record"},{"cve":"CVE-2026-10723","cvss":6.8,"slug":"cve-2026-10723-isc-bind-incorrect-nsec3-record-validation","title":"ISC BIND incorrect NSEC3 record validation","severity":"medium","exploited":false,"published_at":"2026-07-22T15:16:51.19+00:00","url":"https://junglewise.ai/threats/cve-2026-10723-isc-bind-incorrect-nsec3-record-validation"},{"cve":"CVE-2026-5950","cvss":5.3,"slug":"cve-2026-5950-isc-bind-9-unbounded-resend-loop-in-resolver-state-machine","title":"ISC BIND 9 unbounded resend loop in resolver state machine","severity":"medium","exploited":false,"published_at":"2026-05-20T13:16:40.45+00:00","url":"https://junglewise.ai/threats/cve-2026-5950-isc-bind-9-unbounded-resend-loop-in-resolver-state-machine"},{"cve":"CVE-2026-5947","cvss":7.5,"slug":"cve-2026-5947-isc-bind-9-use-after-free-in-sig-0-validation-during-query-flood","title":"ISC BIND 9 use-after-free in SIG(0) validation during query flood","severity":"high","exploited":false,"published_at":"2026-05-20T13:16:40.303+00:00","url":"https://junglewise.ai/threats/cve-2026-5947-isc-bind-9-use-after-free-in-sig-0-validation-during-query-flood"},{"cve":"CVE-2026-5946","cvss":7.5,"slug":"cve-2026-5946-isc-bind-9-denial-of-service-in-named-via-non-in-dns-classes","title":"ISC BIND 9 denial of service in named via non-IN DNS classes","severity":"high","exploited":false,"published_at":"2026-05-20T13:16:40.157+00:00","url":"https://junglewise.ai/threats/cve-2026-5946-isc-bind-9-denial-of-service-in-named-via-non-in-dns-classes"},{"cve":"CVE-2026-3593","cvss":7.4,"slug":"cve-2026-3593-isc-bind-9-use-after-free-in-dns-over-https-implementation","title":"ISC BIND 9 use-after-free in DNS-over-HTTPS implementation","severity":"high","exploited":false,"published_at":"2026-05-20T13:16:23.923+00:00","url":"https://junglewise.ai/threats/cve-2026-3593-isc-bind-9-use-after-free-in-dns-over-https-implementation"},{"cve":"CVE-2026-3592","cvss":5.3,"slug":"cve-2026-3592-isc-bind-resource-exhaustion-in-dns-resolver","title":"ISC BIND resource exhaustion in DNS resolver","severity":"medium","exploited":false,"published_at":"2026-05-20T13:16:23.79+00:00","url":"https://junglewise.ai/threats/cve-2026-3592-isc-bind-resource-exhaustion-in-dns-resolver"},{"cve":"CVE-2026-3039","cvss":7.5,"slug":"cve-2026-3039-isc-bind-9-memory-exhaustion-in-gss-api-tkey-negotiation","title":"ISC BIND 9 memory exhaustion in GSS-API TKEY negotiation","severity":"high","exploited":false,"published_at":"2026-05-20T13:16:23.647+00:00","url":"https://junglewise.ai/threats/cve-2026-3039-isc-bind-9-memory-exhaustion-in-gss-api-tkey-negotiation"},{"cve":"CVE-2026-3591","cvss":5.4,"epss":0.0002,"slug":"cve-2026-3591-isc-bind-9-stack-use-after-return-in-sig-0-handling","title":"ISC BIND 9 stack use-after-return in SIG(0) handling","severity":"medium","exploited":false,"published_at":"2026-03-25T14:16:37.297+00:00","url":"https://junglewise.ai/threats/cve-2026-3591-isc-bind-9-stack-use-after-return-in-sig-0-handling"},{"cve":"CVE-2026-3119","cvss":6.5,"epss":0.0001,"slug":"cve-2026-3119-isc-bind-9-denial-of-service-via-tkey-record-in-authenticated","title":"ISC BIND 9 denial of service via TKEY record in authenticated query","severity":"medium","exploited":false,"published_at":"2026-03-25T14:16:37.097+00:00","url":"https://junglewise.ai/threats/cve-2026-3119-isc-bind-9-denial-of-service-via-tkey-record-in-authenticated"},{"cve":"CVE-2026-3104","cvss":7.5,"epss":0.0005,"slug":"cve-2026-3104-isc-bind-9-memory-leak-in-dnssec-proof-of-non-existence-code","title":"ISC BIND 9 memory leak in DNSSEC proof-of-non-existence code","severity":"high","exploited":false,"published_at":"2026-03-25T14:16:36.89+00:00","url":"https://junglewise.ai/threats/cve-2026-3104-isc-bind-9-memory-leak-in-dnssec-proof-of-non-existence-code"},{"cve":"CVE-2026-1519","cvss":7.5,"epss":0.0003,"slug":"cve-2026-1519-isc-bind-9-denial-of-service-via-excessive-nsec3-iterations","title":"ISC BIND 9 denial of service via excessive NSEC3 iterations","severity":"high","exploited":false,"published_at":"2026-03-25T14:16:33.11+00:00","url":"https://junglewise.ai/threats/cve-2026-1519-isc-bind-9-denial-of-service-via-excessive-nsec3-iterations"},{"cve":"CVE-2025-13878","cvss":7.5,"epss":0.0757,"slug":"cve-2025-13878-isc-bind-9-denial-of-service-via-malformed-brid-or-hhit-records","title":"ISC BIND 9 denial of service via malformed BRID or HHIT records","severity":"high","exploited":false,"published_at":"2026-01-21T15:16:05.65+00:00","url":"https://junglewise.ai/threats/cve-2025-13878-isc-bind-9-denial-of-service-via-malformed-brid-or-hhit-records"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Isc BIND","slug":"bind","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/bind"},{"name":"Isc BIND 9 Supported Preview Edition","slug":"bind-9-supported-preview-edition","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/bind-9-supported-preview-edition"},{"name":"Isc InterNetNews","slug":"internetnews","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/internetnews"}],"technology":{"hub":true,"name":"Isc BIND 9","slug":"bind-9","vendor":{"name":"Isc","slug":"isc","url":"https://junglewise.ai/threats/vendors/isc"},"aliases":[],"category":"web-server","homepage":"https://www.isc.org/bind/","repo_url":"https://gitlab.isc.org/isc-projects/bind9","description":"BIND 9 is a widely used open-source Domain Name System (DNS) software suite.","url":"https://junglewise.ai/threats/technologies/bind-9"},"most_severe":[{"cve":"CVE-2026-13321","cvss":8.6,"slug":"cve-2026-13321-isc-bind-dnssec-validation-bypass-in-nsec-records","title":"ISC BIND DNSSEC validation bypass in NSEC records","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:52.2+00:00","url":"https://junglewise.ai/threats/cve-2026-13321-isc-bind-dnssec-validation-bypass-in-nsec-records"},{"cve":"CVE-2025-13878","cvss":7.5,"epss":0.0757,"slug":"cve-2025-13878-isc-bind-9-denial-of-service-via-malformed-brid-or-hhit-records","title":"ISC BIND 9 denial of service via malformed BRID or HHIT records","severity":"high","exploited":false,"published_at":"2026-01-21T15:16:05.65+00:00","url":"https://junglewise.ai/threats/cve-2025-13878-isc-bind-9-denial-of-service-via-malformed-brid-or-hhit-records"},{"cve":"CVE-2026-3104","cvss":7.5,"epss":0.0005,"slug":"cve-2026-3104-isc-bind-9-memory-leak-in-dnssec-proof-of-non-existence-code","title":"ISC BIND 9 memory leak in DNSSEC proof-of-non-existence code","severity":"high","exploited":false,"published_at":"2026-03-25T14:16:36.89+00:00","url":"https://junglewise.ai/threats/cve-2026-3104-isc-bind-9-memory-leak-in-dnssec-proof-of-non-existence-code"},{"cve":"CVE-2026-1519","cvss":7.5,"epss":0.0003,"slug":"cve-2026-1519-isc-bind-9-denial-of-service-via-excessive-nsec3-iterations","title":"ISC BIND 9 denial of service via excessive NSEC3 iterations","severity":"high","exploited":false,"published_at":"2026-03-25T14:16:33.11+00:00","url":"https://junglewise.ai/threats/cve-2026-1519-isc-bind-9-denial-of-service-via-excessive-nsec3-iterations"},{"cve":"CVE-2026-13204","cvss":7.5,"slug":"cve-2026-13204-isc-bind-9-denial-of-service-via-nsec-and-nsec3-assertion-failure","title":"ISC BIND 9 denial of service via NSEC and NSEC3 assertion failure","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:52.08+00:00","url":"https://junglewise.ai/threats/cve-2026-13204-isc-bind-9-denial-of-service-via-nsec-and-nsec3-assertion-failure"},{"cve":"CVE-2026-12617","cvss":7.5,"slug":"cve-2026-12617-isc-bind-9-denial-of-service-via-cname-or-dname-record-ordering","title":"ISC BIND 9 denial of service via CNAME or DNAME record ordering","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:51.963+00:00","url":"https://junglewise.ai/threats/cve-2026-12617-isc-bind-9-denial-of-service-via-cname-or-dname-record-ordering"},{"cve":"CVE-2026-11721","cvss":7.5,"slug":"cve-2026-11721-isc-bind-9-cache-poisoning-via-rrsig-label-count-discrepancy","title":"ISC BIND 9 cache poisoning via RRSIG label count discrepancy","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:51.837+00:00","url":"https://junglewise.ai/threats/cve-2026-11721-isc-bind-9-cache-poisoning-via-rrsig-label-count-discrepancy"},{"cve":"CVE-2026-11622","cvss":7.5,"slug":"cve-2026-11622-isc-bind-9-resource-exhaustion-in-dnssec-validating-resolver","title":"ISC BIND 9 resource exhaustion in DNSSEC validating resolver","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:51.703+00:00","url":"https://junglewise.ai/threats/cve-2026-11622-isc-bind-9-resource-exhaustion-in-dnssec-validating-resolver"},{"cve":"CVE-2026-11605","cvss":7.5,"slug":"cve-2026-11605-isc-bind-9-resource-exhaustion-in-dnssec-validation","title":"ISC BIND 9 resource exhaustion in DNSSEC validation","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:51.573+00:00","url":"https://junglewise.ai/threats/cve-2026-11605-isc-bind-9-resource-exhaustion-in-dnssec-validation"},{"cve":"CVE-2026-11331","cvss":7.5,"slug":"cve-2026-11331-isc-bind-9-rpz-policy-bypass-and-denial-of-service","title":"ISC BIND 9 RPZ policy bypass and denial of service","severity":"high","exploited":false,"published_at":"2026-07-22T15:16:51.457+00:00","url":"https://junglewise.ai/threats/cve-2026-11331-isc-bind-9-rpz-policy-bypass-and-denial-of-service"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}