Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

General Security Talk, Announcements and News
Post Reply
Starburst-David
Posts: 314
Joined: Wed Feb 11, 2026 8:31 pm

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Post by Starburst-David »

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.

An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.

Full article at:
https://thehackernews.com/2026/09/criti ... -flaw.html

Published Date: Sep 17, 2026

Vulnerabilities has been mentioned in this article:
CVE-2026-85501 CVE-2026-82720 CVE-2026-82717 CVE-2026-81642 CVE-2026-81634 CVE-2026-80225 CVE-2026-78227 CVE-2026-77955 CVE-2026-77860 CVE-2026-33278
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “General”