VORANT. Threat Intelligence Sign in Get the full feed

CERT-FR advisory on multiple ISC BIND flaws

routine vulnerability technologyinfrastructuretelecommunications

CERT-FR advises on eight new vulnerabilities in ISC BIND DNS software that could enable remote denial of service, data integrity compromise, or security bypass.

CERT-FR issued an advisory covering eight distinct CVEs affecting ISC BIND, the widely deployed open-source DNS server software. The vulnerabilities affect BIND Supported Preview Edition versions prior to 9.20.29-S1, BIND 9.21.x versions prior to 9.21.26, and BIND versions prior to 9.20.29. Collectively, these flaws could allow an attacker to trigger a remote denial of service, compromise data integrity, or bypass security policy enforcement on affected DNS servers.

No exploitation in the wild is mentioned in the advisory. CERT-FR directs administrators to ISC's own security bulletins for each CVE for technical details and patches. Given BIND's critical role in DNS infrastructure, organizations running affected versions should prioritize applying the vendor-supplied patches to the fixed versions noted above.

Mentioned in this report

Vulnerabilities CVE-2026-75029CVE-2026-76163CVE-2026-77119CVE-2026-77692CVE-2026-78301CVE-2026-80274CVE-2026-81563CVE-2026-81736

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1192

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free