# CERT-FR advisory on multiple ISC BIND flaws

Published: 2026-09-17 · Severity: routine · Sectors: technology, infrastructure, telecommunications
Canonical: https://vorant.io/reports/392ac586-3a91-5ec5-8ce7-edfdfb642807/cert-fr-advisory-on-multiple-isc-bind-flaws

> CERT-FR advises on eight new vulnerabilities in ISC BIND DNS software that could enable remote denial of service, data integrity compromise, or security bypass.

CERT-FR issued an advisory covering eight distinct CVEs affecting ISC BIND, the widely deployed open-source DNS server software. The vulnerabilities affect BIND Supported Preview Edition versions prior to 9.20.29-S1, BIND 9.21.x versions prior to 9.21.26, and BIND versions prior to 9.20.29. Collectively, these flaws could allow an attacker to trigger a remote denial of service, compromise data integrity, or bypass security policy enforcement on affected DNS servers.

No exploitation in the wild is mentioned in the advisory. CERT-FR directs administrators to ISC's own security bulletins for each CVE for technical details and patches. Given BIND's critical role in DNS infrastructure, organizations running affected versions should prioritize applying the vendor-supplied patches to the fixed versions noted above.

## Mentioned in this report

- Vulnerabilities: CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1192

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/392ac586-3a91-5ec5-8ce7-edfdfb642807/cert-fr-advisory-on-multiple-isc-bind-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
