Find notable cyber news and cases, enriched with sources, timelines, and signals.

ISC BIND 9.20.29 and 9.21.26 security update for 14 flaws

Security Patch Release
First reported
Last updated
Happening score
H score 17
1 unique sources, 1 articles

Summary

Hide ▲

ISC released BIND 9.20.29 and 9.21.26 to fix 14 security flaws in its open-source DNS server, reducing crash, cache-poisoning, and denial-of-service risk for affected deployments. The package also includes 9.20.29-S1 for supported preview customers, while ISC says it is not aware of exploitation and lists no workarounds.

Related Happenings

NLnet Labs security patch release for CVE-2026-81642

Security Patch Release
H score39 First: 17.09.2026 15:30 Last: 17.09.2026 15:30 Sources 1

About this happening: NLnet Labs released Unbound 1.26.1 to close nine security flaws, including CVE-2026-81642 in the DNSSEC validator. The update addresses a critical heap overf...

CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM

Public Sector Action
H score46 First: 26.06.2026 15:31 Last: 26.06.2026 15:31 Sources 1

About this happening: CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...

Timeline

  1. 17.09.2026 11:00 1 articles · 7h ago

    ISC discloses fourteen BIND 9 security flaws

    Initial Disclosure

    ISC disclosed fourteen security flaws in BIND 9, including crashes in named over DNS-over-HTTPS and TKEY, resolver crashes tied to crafted responses, cache-exhaustion conditions in SVCB/HTTPS alias handling, DNSSEC validation downgrades, TSIG-related transfer handling problems, and malformed-zone delegation confusion.

    Show sources
  2. 17.09.2026 11:00 2 articles · 7h ago

    ISC releases BIND 9.20.29, 9.21.26, and 9.20.29-S1

    Mitigation Patch Update

    ISC released BIND 9.20.29, 9.21.26, and 9.20.29-S1 to fix the fourteen disclosed flaws; 9.21.26 covers thirteen issues because CVE-2026-19662 does not affect 9.21, and ISC said it is not aware of active exploitation or any workarounds.

    Show sources