VORANT. Threat Intelligence Sign in Get the full feed

ISC disclosed CVE-2025-13878, a denial-of-service vulnerability in BIND 9 that allows…

high vulnerability

ISC disclosed CVE-2025-13878, a denial-of-service vulnerability in BIND 9 that allows remote attackers to crash DNS servers; patches are available.

The Internet Systems Consortium (ISC) has published a security advisory regarding a denial-of-service vulnerability (CVE-2025-13878) affecting BIND 9, one of the most widely deployed DNS server implementations. The vulnerability allows a remote unauthenticated attacker to cause abnormal termination of the DNS service, potentially disrupting name resolution for affected networks.

As of the advisory date (January 23, 2026), no active exploitation has been observed in the wild. However, given the critical role DNS plays in network infrastructure and the remote exploitability of the flaw, ISC and Japan's IPA (Information-technology Promotion Agency) emphasize that attacks may emerge. DNS server administrators are urged to upgrade immediately to one of the patched versions.

ISC has released patches across multiple BIND 9 branches: 9.18.44, 9.20.18, 9.21.17, and Supported Preview Edition versions 9.18.44-S1 and 9.20.18-S1. Organizations running BIND 9 DNS servers should prioritize testing and deploying these updates to mitigate the risk of service disruption.

Mentioned in this report

Vulnerabilities CVE-2025-13878

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20260123.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free