CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

September 17, 2026

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Swati KhandelwalSep 17, 2026Vulnerability / DNS Security Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with eight other flaws. One of the eight, CVE-2026-82717, is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic. It could also lead to remote code execution "under certain systems and compilation options," NLnet Labs said. NLnet…

CVEs: CVE-2026-81642, CVE-2026-82717, CVE-2026-33278, CVE-2026-81634, CVE-2026-77955, CVE-2026-78227, CVE-2026-80225, CVE-2026-82720, CVE-2026-85501, CVE-2026-77860