NLnet Labs security patch release for CVE-2026-81642
Security Patch Release
Summary
Hide ▲
Show ▼
NLnet Labs released Unbound 1.26.1 to close nine security flaws, including CVE-2026-81642 in the DNSSEC validator. The update addresses a critical heap overflow that could let an attacker using a malicious zone trigger remote code execution on vulnerable resolvers. The affected range covers every Unbound release before 1.26.1, including 1.26.0 and 1.25.2. NLnet Labs said it has not reported exploitation, and the advisory provides upgrade and patch paths.
Related Happenings
ISC BIND 9.20.29 and 9.21.26 security update for 14 flaws
Security Patch Release
H score17
First: 17.09.2026 11:00
Last: 17.09.2026 11:00
Sources 1
About this happening:
ISC released BIND 9.20.29 and 9.21.26 to fix 14 security flaws in its open-source DNS server, reducing crash, cache-poisoning, and denial-of-service risk for affec...
ISC BIND 9.20.29 and 9.21.26 security update for 14 flaws
Security Patch ReleaseAbout this happening: ISC released BIND 9.20.29 and 9.21.26 to fix 14 security flaws in its open-source DNS server, reducing crash, cache-poisoning, and denial-of-service risk for affec...
Citrix NetScaler urgent patch guidance for CVE-2026-19490
Advisory/Mitigation
H score54
First: 04.09.2026 18:25
Last: 04.09.2026 18:25
Sources 1
About this happening:
Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...
Citrix NetScaler urgent patch guidance for CVE-2026-19490
Advisory/MitigationAbout this happening: Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...
HPE ArubaOS-CX security bulletin (CVE-2026-73749)
Security Patch Release
H score31
First: 03.09.2026 21:28
Last: 03.09.2026 21:28
Sources 1
About this happening:
HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...
HPE ArubaOS-CX security bulletin (CVE-2026-73749)
Security Patch ReleaseAbout this happening: HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...
Cisco security patch release for CVE-2026-20337
Security Patch Release
H score30
First: 11.08.2026 14:03
Last: 11.08.2026 14:03
Sources 1
About this happening:
Cisco released ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338, reducing denial-of-service risk for deployments running ClamAV 1.5.0 through 1.5.3. T...
Cisco security patch release for CVE-2026-20337
Security Patch ReleaseAbout this happening: Cisco released ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338, reducing denial-of-service risk for deployments running ClamAV 1.5.0 through 1.5.3. T...
OpenWrt security patch release for CVE-2026-53921
Security Patch Release
H score37
First: 28.07.2026 15:56
Last: 28.07.2026 15:56
Sources 1
About this happening:
OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
OpenWrt security patch release for CVE-2026-53921
Security Patch ReleaseAbout this happening: OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
Timeline
-
17.09.2026 15:30 1 articles · 2h ago
Yuqi Qiu reports Unbound DNS resolver DNSSEC validator heap overflow to NLnet Labs
Initial DisclosureYuqi Qiu, who found the issue with Xiang Li at Nankai University's AOSP Lab, reported a critical heap overflow in the Unbound DNS resolver's DNSSEC validator to NLnet Labs on August 11. The flaw affects every release before 1.26.1 and can be triggered when an attacker controls a malicious zone and queries a vulnerable resolver, creating denial of service and possible remote code execution.
Show sources
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30
-
17.09.2026 15:30 2 articles · 2h ago
NLnet Labs releases Unbound 1.26.1 to fix CVE-2026-81642 and eight other flaws
Mitigation Patch UpdateNLnet Labs released Unbound 1.26.1 on September 17, 2026, fixing the critical DNSSEC validator heap overflow tracked as CVE-2026-81642 along with eight other flaws. The advisory says the affected range runs through 1.26.0, that neither bug had reported exploitation, and that standalone or combined source patches are available for systems that cannot upgrade.
Show sources
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30