CERT-FR advisory on multiple ISC BIND flaws
CERT-FR advises on eight new vulnerabilities in ISC BIND DNS software that could enable remote denial of service, data integrity compromise, or security bypass.
CERT-FR issued an advisory covering eight distinct CVEs affecting ISC BIND, the widely deployed open-source DNS server software. The vulnerabilities affect BIND Supported Preview Edition versions prior to 9.20.29-S1, BIND 9.21.x versions prior to 9.21.26, and BIND versions prior to 9.20.29. Collectively, these flaws could allow an attacker to trigger a remote denial of service, compromise data integrity, or bypass security policy enforcement on affected DNS servers.
No exploitation in the wild is mentioned in the advisory. CERT-FR directs administrators to ISC's own security bulletins for each CVE for technical details and patches. Given BIND's critical role in DNS infrastructure, organizations running affected versions should prioritize applying the vendor-supplied patches to the fixed versions noted above.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1192
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free