# ISC disclosed CVE-2025-13878, a denial-of-service vulnerability in BIND 9 that allows…

Published: 2026-01-22 · Severity: high
Canonical: https://vorant.io/reports/d2480526-6cdf-431d-b147-3ddb962a233c/isc-disclosed-cve-2025-13878-a-denial-of-service-vulnerability-in-bind-9-that

> ISC disclosed CVE-2025-13878, a denial-of-service vulnerability in BIND 9 that allows remote attackers to crash DNS servers; patches are available.

The Internet Systems Consortium (ISC) has published a security advisory regarding a denial-of-service vulnerability (CVE-2025-13878) affecting BIND 9, one of the most widely deployed DNS server implementations. The vulnerability allows a remote unauthenticated attacker to cause abnormal termination of the DNS service, potentially disrupting name resolution for affected networks.

As of the advisory date (January 23, 2026), no active exploitation has been observed in the wild. However, given the critical role DNS plays in network infrastructure and the remote exploitability of the flaw, ISC and Japan's IPA (Information-technology Promotion Agency) emphasize that attacks may emerge. DNS server administrators are urged to upgrade immediately to one of the patched versions.

ISC has released patches across multiple BIND 9 branches: 9.18.44, 9.20.18, 9.21.17, and Supported Preview Edition versions 9.18.44-S1 and 9.20.18-S1. Organizations running BIND 9 DNS servers should prioritize testing and deploying these updates to mitigate the risk of service disruption.

## Mentioned in this report

- Vulnerabilities: CVE-2025-13878

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20260123.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d2480526-6cdf-431d-b147-3ddb962a233c/isc-disclosed-cve-2025-13878-a-denial-of-service-vulnerability-in-bind-9-that.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
